CVE-2026-8037

CRITICAL WAF: High
CVSS 9.8 Published: 2026-06-04
CWE-77

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints

WAF Coverage Analysis

Command Injection High WAF Coverage

OWASP: A03:2021 Injection

932xxx - Remote Code Execution

Affected Software

VendorProductVersion
progressconnection_manager_for_objectscaleup to 7.2.63.2
progressecs_connection_managerup to 7.2.63.2
progressloadmasterup to 7.2.54.18
progressloadmaster7.2.55.0 - 7.2.63.2

References

Back to CVE Database