CVE-2026-8037 · Critical · CISA KEV

Progress LoadMaster Command Injection: Critical Risk to Network Infrastructure

Threat Engine Auto-Feed · data current as of 2026-08-08

A command injection vulnerability in Progress LoadMaster appliances allows unauthenticated attackers to execute arbitrary commands. This flaw is actively exploited in the wild, as confirmed by its inclusion in CISA KEV, and presents a critical risk to organizations using affected versions. Its high EPSS score indicates a significant likelihood of further exploitation.

  • CVSS:
  • EPSS percentile: 0.99688
  • Exploitation pressure: 85/100 (Critical)

Exploitation reality: listed in CISA KEV (exploited in the wild) · EPSS 100th percentile. Threat × Vulnerability from public signals — impact depends on your environment.

Weakness —

This vulnerability stems from a command injection flaw, meaning the software fails to properly sanitize or validate user-supplied input before incorporating it into system commands. An attacker can insert malicious commands into an input field, which the system then executes with its own privileges, leading to unauthorized actions.

Who's at risk

Exposure: unknown · Auth: unknown · unknown

Enterprise profiles most at risk

  • Organizations utilizing Progress LoadMaster appliances for network load balancing and traffic management
  • Enterprises with critical internal services exposed via LoadMaster
  • Financial services, Technology, and other sectors targeted by sophisticated adversaries

Misconfigurations that escalate it

  • LoadMaster appliances exposed directly to the internet without additional protective measures
  • Lack of robust network segmentation around LoadMaster devices
  • Insufficient logging and monitoring of LoadMaster activity

High-impact scenarios

  • Complete compromise of the LoadMaster appliance, leading to unauthorized control over network traffic
  • Lateral movement within the network by leveraging the compromised LoadMaster as a pivot point
  • Disruption of critical services reliant on LoadMaster for availability and performance
  • Data exfiltration or further system compromise through arbitrary command execution

Likely adversaries

  • FIN7 — Financial services (Assessed)
  • LockBit affiliates — Financial services (Assessed)
  • APT38 (Lazarus) — Financial services (Assessed)
  • APT29 (Cozy Bear) — Technology (Assessed)
  • Scattered Spider — Technology (Assessed)

What to do (defensive)

Detect

  • Monitor LoadMaster logs for unusual command execution patterns or unauthorized access attempts.
  • Implement network intrusion detection systems (NIDS) to identify suspicious traffic originating from or destined for LoadMaster appliances.
  • Regularly audit LoadMaster configurations for any unauthorized changes.

Contain

  • Isolate affected LoadMaster appliances from the broader network if compromise is suspected.
  • Restrict network access to LoadMaster management interfaces to only trusted IP ranges.
  • Implement strong access controls and multi-factor authentication for LoadMaster administration.

Patch

  • Apply vendor-provided security patches for Progress LoadMaster immediately upon availability.
  • Follow vendor guidance for securing LoadMaster deployments and mitigating known vulnerabilities.

Frontier verdict — Critical

This is a critical, actively exploited vulnerability in Progress LoadMaster with a very high EPSS, demanding immediate patching and defensive measures to prevent unauthenticated command execution.

For detection-engineering and awareness only · point-in-time · not security advice · sourced from NVD, FIRST EPSS, CISA KEV. Adversary mappings are assessments unless cited.