OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF
100Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 9.6epss 99%
from disclosure to weapon26 days
Published on NVDJun 4
1st PoC+26d
VulnCheck+27d
exploitation probability
99%top 1% of all CVEs
observed exploitation
yesVulnCheck
4 public exploit(s)
Action required by CISAfederal deadline: 2026-08-10
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products
Progress Software · ECS Connections ManagerProgress Software · LoadMasterProgress Software · MOVEit WAFProgress Software · Object Scale Connection Managerpublic PoCs found — 4
githubgithub.com/HORKimhab/CVE-2026-8037★ 0githubgithub.com/Caster-chen/CVE-2026-8037-POC★ 0cve_referencelabs.watchtowr.com/enterprise-tech-in-shell-out-progress-kemp-loadmaster-uninitialized-heap-to-pre-auth-rce-cve-2026-8037/unverifiedvulncheckvulncheck.com/xdb/97b565af3d60unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.