9.6
/ 10
CRITICAL
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Description
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints
AI Analysis
OS Command Injection vulnerability allowing remote code execution on Progress LoadMaster and related products
Basic Information
ID
CVE-2026-8037
Source
ProgressSoftware
Published
Jun 4, 2026 at 13:13
Affected Product
Vendor
Progress Software
Product
LoadMaster
Version
V7.2.60.0
Affected Versions
Progress Software LoadMaster V7.2.60.0
Progress Software LoadMaster V7.2.45.12
Progress Software ECS Connections Manager V7.2.60.0
Progress Software Object Scale Connection Manager V7.2.60.0
Progress Software MOVEit WAF V7.2.60.0
Progress Software LoadMaster V7.2.45.12
Progress Software ECS Connections Manager V7.2.60.0
Progress Software Object Scale Connection Manager V7.2.60.0
Progress Software MOVEit WAF V7.2.60.0
CWE Classification
AI Assessment
AI Score
9.6 / 10
AI Severity
Critical
Vendor
Progress Software
Product
LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF
Version
V7.2.60.0, V7.2.45.12