CVE-2026-8037 – Progress LoadMaster

CVSS 9.6 CRITICAL Zero Day – Immediate Deployment

“A public exploit turns an exposed LoadMaster API into a direct path for remote command execution.”

CVE-2026-8037 is a Critical OS command injection vulnerability affecting Progress LoadMaster. The flaw allows an unauthenticated remote attacker to execute arbitrary commands through vulnerable API functionality. The CVSS score is 9.6, which is Critical severity.

Progress addressed the vulnerability in updated LoadMaster releases. Public proof-of-concept exploit code is available, significantly increasing the risk to unpatched systems.

Key Details

Affected Product
Progress Connection Manager For Objectscale
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-77
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.