DIRAS TAKE
Urgent: CISA placed this CVE on its Known Exploited Vulnerabilities list with a federal remediation deadline of 2026-08-10, indicating immediate patching or mitigation is required for exposed systems.
What is CVE-2026-8037?
An unauthenticated attacker can execute arbitrary OS commands on Progress LoadMaster appliances, allowing full system compromise (CVE-2026-8037). The flaw is a command injection in API endpoints that accept unsanitized input. Affected LoadMaster builds include V7.2.60.0 up to but not including V7.2.63.2 and V7.2.45.12 up to but not including V7.2.54.18; related components (ECS Connections Manager, Object Scale Connection Manager, MOVEit WAF) share the same affected ranges. The vulnerability requires only network access to a vulnerable appliance and no authentication or user interaction. The weakness is classified as CWE-77 (Command Injection).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Progress LoadMaster are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| LoadMaster | V7.2.60.0 – before V7.2.63.2 | V7.2.63.2 |
| LoadMaster | V7.2.45.12 – before V7.2.54.18 | V7.2.54.18 |
| ECS Connections Manager | V7.2.60.0 – before V7.2.63.2 | V7.2.63.2 |
| Object Scale Connection Manager | V7.2.60.0 – before V7.2.63.2 | V7.2.63.2 |
| MOVEit WAF | V7.2.60.0 – before V7.2.63.2 | V7.2.63.2 |
Is CVE-2026-8037 being exploited?
CISA added CVE-2026-8037 to the Known Exploited Vulnerabilities catalog on 2026-08-07, and U.S. federal agencies must remediate by 2026-08-10; public exploit code is also available.
How to fix CVE-2026-8037
- Apply vendor updates to fixed releases: upgrade to V7.2.63.2 or V7.2.54.18 depending on your installed branch.
- If you cannot update immediately, restrict network exposure of LoadMaster management/API interfaces to trusted hosts and management networks.
- Follow the vendor’s mitigation guidance and monitor appliance logs and network traffic for suspicious command execution or unexpected processes.
- Treat internet-facing instances as high priority for patching in accordance with BOD 26-04 guidance.
Frequently asked questions
Is CVE-2026-8037 being actively exploited?
CISA added CVE-2026-8037 to its Known Exploited Vulnerabilities catalog on 2026-08-07, and U.S. federal agencies were required to remediate by 2026-08-10; public exploit code is also available.
Which LoadMaster versions are affected by CVE-2026-8037?
LoadMaster builds V7.2.60.0 through before V7.2.63.2 and V7.2.45.12 through before V7.2.54.18 are listed as affected, as are the same ranges for ECS Connections Manager, Object Scale Connection Manager, and MOVEit WAF.
Is there a patch for CVE-2026-8037?
Yes. Progress published fixes; the vulnerability is corrected in V7.2.63.2 and V7.2.54.18 depending on the affected branch.
Does CVE-2026-8037 require authentication?
No. The vulnerability allows unauthenticated command execution against vulnerable LoadMaster API endpoints and requires only network access to the service.
References
- nvd.nist.gov/vuln/detail/CVE-2026-8037
- cve.org/CVERecord?id=CVE-2026-8037
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-8037
- community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691
- All Progress CVEs on CVE Radar
- CVEs published in September 2026