PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jul 1, 2026

Progress ADC LoadMaster - Command Injection

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
3.1k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2026-8037
9.6
CVSScritical
Exploitable from an adjacent network · no authentication required.

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints

Attack Vector
Adjacent
Privileges Req.
None
User Interaction
None
Affected
LoadMasterby Progress Software
AFFECTED< V7.2.63.2SAFE ✓≥ V7.2.63.2
ECS Connections Managerby Progress Software
AFFECTED< V7.2.63.2SAFE ✓≥ V7.2.63.2
Object Scale Connection Managerby Progress Software
AFFECTED< V7.2.63.2SAFE ✓≥ V7.2.63.2
MOVEit WAFby Progress Software
AFFECTED< V7.2.63.2SAFE ✓≥ V7.2.63.2
Updated Sep 9, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

Progress ADC LoadMaster - Command Injection Scanner | S4E