Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3436 articles · 210641 vulns · 37/41 feeds (7d)
← Back to list
9.6
CVE-2026-8037KEVEXPLOITEDPATCHED
progress · connection_manager_for_objectscale

OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF

Description

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints

Affected Products

VendorProductVersions
progressconnection_manager_for_objectscaleV7.2.60.0, V7.2.45.12, V7.2.60.0, V7.2.60.0, V7.2.60.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
kemploadmastercert_advisory90%
progressmoveit_web_application_firewallcve_cpe95%
progressecs_connection_managercve_cpe95%
progressloadmastercve_cpe95%

References

  • https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691(vendor-advisory)
  • https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-8037.yaml(exploit, nuclei)

Related News (12 articles)

Tier D
Heise Security26d ago
Schadcode-Attacken auf Progress LoadMaster im Gange
→ No new info (linked only)
Tier D
BleepingComputer26d ago
Critical Progress LoadMaster flaw now actively exploited in attacks
→ No new info (linked only)
Tier D
SecurityWeek26d ago
CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability
→ No new info (linked only)
Tier D
The Hacker News28d ago
Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts
→ No new info (linked only)
Tier B
CERT-FR48d ago
Bulletin d'actualité CERTFR-2026-ACT-031 (20 juillet 2026)
→ No new info (linked only)
Tier B
CERT-FR53d ago
Multiples vulnérabilités dans Progress LoadMaster (15 juillet 2026)
→ No new info (linked only)
Tier D
The Hacker News66d ago
Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts
→ No new info (linked only)
Tier D
The Hacker News67d ago
Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth
→ No new info (linked only)
Tier E
Reddit r/cybersecurity68d ago
Enterprise Tech In, Shell Out (Progress Kemp LoadMaster Uninitialized Heap to Pre-Auth RCE CVE-2026-8037) - watchTowr Labs
→ No new info (linked only)
Tier E
Reddit r/netsec68d ago
Enterprise Tech In, Shell Out (Progress Kemp LoadMaster Uninitialized Heap to Pre-Auth RCE CVE-2026-8037) - watchTowr Labs
→ No new info (linked only)
Tier B
BSI Advisories89d ago
[NEU] [hoch] Kemp LoadMaster: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB93d ago
CVE-2026-8037 | Progress LoadMaster API command injection
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.19.6 CRITICAL
VectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
null
CWECWE-77
PublishedJun 4, 2026
Last enriched52d agov3
Trending Score4
Source articles12
Independent9
Info Completeness11/14
Missing: epss, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-18672
RadImageEditor ClientState Unauthenticated Arbitrary File Read Vulnerability in Telerik UI for ASP.NET AJAX
Trending: 32
HIGHCVE-2026-19219
DialogHandler UploadPaths Tampering Vulnerability in Telerik UI for ASP.NET AJAX
Trending: 28
HIGHCVE-2026-16139
Arbitrary file write via path traversal in Progress ShareFile Storage Zones Controller potentially leading to remote code execution
Trending: 6
HIGHCVE-2026-16138
Remote code execution via unsafe deserialization in Progress ShareFile Storage Zones Controller's CICO service
Trending: 6
HIGHCVE-2026-16137
Path traversal via unsanitized upload filename leads to arbitrary file write in Progress ShareFile Storage Zones Controller
Trending: 6

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 4, 2026
Added to CISA KEV
Jun 4, 2026
Discovered by ZDM
Jun 4, 2026
Updated: description, patchAvailable
Jun 4, 2026
Updated: affectedVersions
Jul 15, 2026
Actively Exploited
Aug 8, 2026
Exploit Available
Aug 8, 2026
Patch Available
Aug 8, 2026

Version History

v3
Last enriched 52d ago
v3Tier B52d ago

Updated affected versions to include v7.2.63.2 and v7.2.54.18.

affectedVersions
via CERT-FR
v2Tier C93d ago

Updated description with more technical detail and corrected exploit availability to false.

descriptionpatchAvailable
via VulDB
v193d ago

Initial creation