[KEV] CVE-2026-8037 -- CVSS 0.0 Vulnerability Briefing
[KEV] CVE-2026-8037 | CVSS 0.0 (Low) | Exploit: Operational
What Is It
CVE-2026-8037 is an unauthenticated command injection vulnerability in multiple command endpoints on Progress LoadMaster appliances.
Technical Detail
The flaw results from unsanitized input being passed to command-processing endpoints. An unauthenticated remote attacker can submit crafted input to execute arbitrary operating system commands on an affected LoadMaster appliance. Successful exploitation can result in remote code execution with the privileges of the vulnerable service.
Exploitation Status
Exploit maturity is operational, meaning exploitation capability is usable in real-world intrusions rather than limited to a theoretical proof of concept. CISA has confirmed active exploitation in the wild. The vulnerability was added to the CISA Known Exploited Vulnerabilities Catalog on August 7, 2026.
Who Is Targeting This
No specific threat actor attribution at this time.
What To Do
Prioritize installation of the vendor-provided security update or fixed LoadMaster release as soon as it is available. Under CISA Binding Operational Directive 22-01 requirements, federal civilian executive branch agencies must patch by August 28, 2026 or apply mitigations. Until remediation is complete, restrict access to LoadMaster management and command endpoints to trusted administrative networks, do not expose them directly to the internet, and review appliance and network logs for unexpected requests to command endpoints, unusual command execution, configuration changes, or outbound connections from the appliance. Specific indicators of compromise and vendor workarounds have not been provided in the available data.