CVE-2026-8037CISA KEVEPSS p99.5%

CVE-2026-8037Progress LoadMaster Command Injection Vulnerability

Progress / LoadMaster

Description

Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.

Scoring

CVSS 9.6 ()
VectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS77.36% probability of exploitation · percentile 99.5% · 2026-10-06T12:00:23Z
Last modified2026-10-01

CISA KEV entry

Added to KEV: 2026-08-07

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
Progress Kemp LoadMaster OS Command Injection Vulnerability
CVE
CVE-2025-1758
CVE
CVE-2026-10727
CVE
CVE-2025-41709
CVE
CVE-2026-44866
CVE
CVE-2026-3692
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.