{"id":"CVE-2026-8037","title":"OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command en…","summary":"OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command en…","severity":"critical","cvss":9.6,"cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-77"],"vendor":"progress","product":"connection_manager_for_objectscale","affected":["connection_manager_for_objectscale < 7.2.63.2","ecs_connection_manager < 7.2.63.2","loadmaster < 7.2.54.18","loadmaster >= 7.2.55.0, < 7.2.63.2"],"patched":["connection_manager_for_objectscale 7.2.63.2","ecs_connection_manager 7.2.63.2","loadmaster 7.2.63.2"],"published":"2026-06-04","updated":"2026-07-13","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-8037","references":[{"url":"https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691","label":"security@progress.com"},{"url":"https://labs.watchtowr.com/enterprise-tech-in-shell-out-progress-kemp-loadmaster-uninitialized-heap-to-pre-auth-rce-cve-2026-8037/","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild","exploit-available"],"epss":0.99571,"epssPercentile":0.99946,"ingestedAt":"2026-07-13T19:28:40.446Z","kev":true,"exploited":true,"kevDateAdded":"2026-08-07","kevDueDate":"2026-08-10","kevRansomware":false,"exploits":{"github":2,"githubRepos":["https://github.com/HORKimhab/CVE-2026-8037","https://github.com/Caster-chen/CVE-2026-8037-POC"],"nuclei":["CVE-2026-8037"],"checkedAt":"2026-09-15T16:16:08.269Z"},"exploitAvailable":true,"slug":"CVE-2026-8037","body":"## Overview\n\nOS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints\n\n## Affected\n\n- `connection_manager_for_objectscale < 7.2.63.2`\n- `ecs_connection_manager < 7.2.63.2`\n- `loadmaster < 7.2.54.18`\n- `loadmaster >= 7.2.55.0, < 7.2.63.2`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `connection_manager_for_objectscale 7.2.63.2`\n- `ecs_connection_manager 7.2.63.2`\n- `loadmaster 7.2.63.2`","depth":"hadal","depthScore":98,"depthScoreParts":{"impact":52.8,"likelihood":19.9,"exploitation":25,"ransomware":0},"changes":[{"seq":5489,"id":"CVE-2026-8037","ts":1788887289153,"field":"exploit_available","old":"false","new":"true"},{"seq":4367,"id":"CVE-2026-8037","ts":1788886401571,"field":"exploit_available","old":"true","new":"false"},{"seq":3083,"id":"CVE-2026-8037","ts":1788883065432,"field":"exploit_available","old":"false","new":"true"},{"seq":2112,"id":"CVE-2026-8037","ts":1788882469676,"field":"exploit_available","old":"true","new":"false"},{"seq":1178,"id":"CVE-2026-8037","ts":1788881906945,"field":"exploit_available","old":"false","new":"true"},{"seq":125,"id":"CVE-2026-8037","ts":1786218573581,"field":"epss","old":"0.84793","new":"0.99311"},{"seq":123,"id":"CVE-2026-8037","ts":1786131751319,"field":"exploited","old":"false","new":"true"},{"seq":122,"id":"CVE-2026-8037","ts":1786131751319,"field":"kev","old":"false","new":"true"},{"seq":98,"id":"CVE-2026-8037","ts":1784920500230,"field":"epss","old":"0.4343","new":"0.84793"},{"seq":65,"id":"CVE-2026-8037","ts":1784055479238,"field":"epss","old":"0.29641","new":"0.4343"}]}