cognitive cybersecurity intelligence

News and Analysis

Search

CISA Warns of Progress LoadMaster Command Injection Vulnerability Exploited in Attacks

CISA Warns of Progress LoadMaster Command Injection Vulnerability Exploited in Attacks

CISA has added a critical Progress LoadMaster vulnerability to its Known Exploited Vulnerabilities catalog after attackers were observed targeting exposed devices. Tracked as CVE-2026-8037, the flaw affects Progress LoadMaster and Progress ADC products.

It is a command injection issue that could let an unauthenticated attacker run arbitrary commands on a vulnerable LoadMaster appliance. The vulnerability has a CVSS severity score of 9.6, placing it in the critical category.

LoadMaster is an application delivery controller and load balancer used by organizations to manage, distribute, and secure network traffic. Because these appliances often sit at critical network points, a successful compromise can provide attackers with a valuable path into an organization’s environment.

Progress LoadMaster Command Injection Vulnerability Exploited

CISA said the issue exists because multiple command endpoints do not properly sanitize input. An attacker can send specially crafted data to these endpoints and inject operating system commands.

No valid account or authentication is required to begin exploitation, making internet-facing appliances especially exposed. The weakness is classified as CWE-77, which refers to improper neutralization of special elements in operating system commands.

Security researchers first disclosed the flaw on June 4, 2026. Functional proof-of-concept exploit code became public on June 29, 2026. Soon after, eSentire’s Threat Response Unit identified attempts to exploit the vulnerability.

While the initial activity did not result in confirmed post-compromise activity, the release of working exploit code increases the risk of broader abuse.

Reports indicate that attackers made hundreds of attempts to exploit the flaw from dozens of IP addresses across multiple countries. This activity shows that threat actors are actively scanning for vulnerable LoadMaster deployments and attempting to gain remote code execution.

CISA added CVE-2026-8037 to the KEV catalog on August 7, 2026, and set August 10, 2026, as the remediation deadline for U.S. federal civilian agencies.

The agency has not confirmed whether the vulnerability has been used in ransomware campaigns. However, remote code execution flaws in network appliances are often valuable to initial access operators and ransomware affiliates.

Organizations using Progress LoadMaster should immediately review vendor guidance and apply the available security updates. Security teams should identify all LoadMaster appliances, confirm software versions, and determine whether management interfaces or APIs are accessible from the internet.

Where patching cannot occur immediately, administrators should restrict access to trusted networks, disable unnecessary external management services, and monitor logs for suspicious API requests or unexpected configuration changes. Teams should also perform incident triage to identify possible compromise before and after remediation.

CISA advises stakeholders to follow Binding Operational Directive 26-04 risk-based patching requirements, assess each asset’s internet exposure, and discontinue use of affected products if effective mitigations are unavailable.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.
The post CISA Warns of Progress LoadMaster Command Injection Vulnerability Exploited in Attacks appeared first on Cyber Security News.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts

The State of Biotech 2026

The State of Biotech 2026

John Maraganore, PhD Co-Founder and Executive ChairCity Therapeutics View Bio Panelist John Maraganore, PhD John Maraganore, PhD, is a co-founder and executive chair of City