CVE-2026-8037Critical· 9.6▾ Hadal⚠ Exploited in the wildPoC availableOS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command en…
▾ Hadal zone — Critical and actively exploited (CISA KEV / 0day)
impact 52.8 · likelihood 19.9 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 2 sources. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
30%
Federal remediation due Aug 10, 2026
30% → 100%
2 GitHub repos · Nuclei ×1
Added to the CISA catalog on Aug 7, 2026. Federal remediation due Aug 10, 2026. View catalog ↗
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints
connection_manager_for_objectscale < 7.2.63.2ecs_connection_manager < 7.2.63.2loadmaster < 7.2.54.18loadmaster >= 7.2.55.0, < 7.2.63.2Upgrade past the affected range:
connection_manager_for_objectscale 7.2.63.2ecs_connection_manager 7.2.63.2loadmaster 7.2.63.2Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2024-55956Critical· 9.8In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Aut…
CVE-2025-10035Critical· 10.0A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.
CVE-2024-21887Critical· 9.1A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the…
CVE-2017-11357Critical· 9.8Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
CVE-2018-19949Critical· 9.8If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands
CVE-2024-1212Critical· 10.0Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.