CVE-2026-8037
CRITICAL WAF: High
CVSS 9.8
Published: 2026-06-04
CWE-77
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints
WAF Coverage Analysis
Command Injection
High WAF Coverage
OWASP: A03:2021 Injection
932xxx - Remote Code Execution
Affected Software
| Vendor | Product | Version |
|---|---|---|
| progress | connection_manager_for_objectscale | up to 7.2.63.2 |
| progress | ecs_connection_manager | up to 7.2.63.2 |
| progress | loadmaster | up to 7.2.54.18 |
| progress | loadmaster | 7.2.55.0 - 7.2.63.2 |
References
- community.progress.com (Vendor Advisory, Patch)
- labs.watchtowr.com (Exploit, Patch, Third Party Advisory)