Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4358 articles · 196331 vulns · 36/41 feeds (7d)
← Back to list
9.6
CVE-2026-8037KEVEXPLOITEDPATCHED
progress · connection_manager_for_objectscale

OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF

Description

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints

Affected Products

VendorProductVersions
progressconnection_manager_for_objectscaleV7.2.60.0, V7.2.45.12, V7.2.60.0, V7.2.60.0, V7.2.60.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
kemploadmastercert_advisory90%
progressmoveit_web_application_firewallcve_cpe95%
progressecs_connection_managercve_cpe95%
progressloadmastercve_cpe95%

References

  • https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691(vendor-advisory)
  • https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-8037.yaml(exploit, nuclei)

Related News (12 articles)

Tier D
Heise Security13d ago
Schadcode-Attacken auf Progress LoadMaster im Gange
→ No new info (linked only)
Tier D
BleepingComputer13d ago
Critical Progress LoadMaster flaw now actively exploited in attacks
→ No new info (linked only)
Tier D
SecurityWeek13d ago
CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability
→ No new info (linked only)
Tier D
The Hacker News15d ago
Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts
→ No new info (linked only)
Tier B
CERT-FR35d ago
Bulletin d'actualité CERTFR-2026-ACT-031 (20 juillet 2026)
→ No new info (linked only)
Tier B
CERT-FR40d ago
Multiples vulnérabilités dans Progress LoadMaster (15 juillet 2026)
→ No new info (linked only)
Tier D
The Hacker News53d ago
Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts
→ No new info (linked only)
Tier D
The Hacker News54d ago
Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth
→ No new info (linked only)
Tier E
Reddit r/cybersecurity55d ago
Enterprise Tech In, Shell Out (Progress Kemp LoadMaster Uninitialized Heap to Pre-Auth RCE CVE-2026-8037) - watchTowr Labs
→ No new info (linked only)
Tier E
Reddit r/netsec55d ago
Enterprise Tech In, Shell Out (Progress Kemp LoadMaster Uninitialized Heap to Pre-Auth RCE CVE-2026-8037) - watchTowr Labs
→ No new info (linked only)
Tier B
BSI Advisories76d ago
[NEU] [hoch] Kemp LoadMaster: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB80d ago
CVE-2026-8037 | Progress LoadMaster API command injection
→ No new info (linked only)
CVSS 3.19.6 CRITICAL
VectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
null
CWECWE-77
PublishedJun 4, 2026
Last enriched39d agov3
Trending Score21
Source articles12
Independent9
Info Completeness11/14
Missing: epss, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-16139
Arbitrary file write via path traversal in Progress ShareFile Storage Zones Controller potentially leading to remote code execution
Trending: 22
HIGHCVE-2026-16138
Remote code execution via unsafe deserialization in Progress ShareFile Storage Zones Controller's CICO service
Trending: 22
HIGHCVE-2026-16137
Path traversal via unsanitized upload filename leads to arbitrary file write in Progress ShareFile Storage Zones Controller
Trending: 22
HIGHCVE-2026-59689
Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF Improper Authorization Allows Privilege Escalation to Root
Trending: 15
HIGHCVE-2026-59690
Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant Missing Authorization Allows Privilege Escalation via REST API
Trending: 15

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 4, 2026
Added to CISA KEV
Jun 4, 2026
Discovered by ZDM
Jun 4, 2026
Updated: description, patchAvailable
Jun 4, 2026
Updated: affectedVersions
Jul 15, 2026
Actively Exploited
Aug 8, 2026
Exploit Available
Aug 8, 2026
Patch Available
Aug 8, 2026

Version History

v3
Last enriched 39d ago
v3Tier B39d ago

Updated affected versions to include v7.2.63.2 and v7.2.54.18.

affectedVersions
via CERT-FR
v2Tier C80d ago

Updated description with more technical detail and corrected exploit availability to false.

descriptionpatchAvailable
via VulDB
v180d ago

Initial creation