{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-8037","assignerOrgId":"f9fea0b6-671e-4eea-8fde-31911902ae05","state":"PUBLISHED","assignerShortName":"ProgressSoftware","dateReserved":"2026-05-06T13:35:25.608Z","datePublished":"2026-06-04T13:13:45.793Z","dateUpdated":"2026-08-08T03:55:14.713Z"},"containers":{"cna":{"providerMetadata":{"orgId":"f9fea0b6-671e-4eea-8fde-31911902ae05","shortName":"ProgressSoftware","dateUpdated":"2026-06-04T13:13:45.793Z"},"title":"OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-77","description":"CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')","type":"CWE"}]}],"impacts":[{"descriptions":[{"lang":"en","value":"An unauthenticated remote attacker exploits unsanitized input in the LoadMaster API command endpoints to inject arbitrary OS commands, resulting in full remote code execution on the appliance."}]}],"affected":[{"vendor":"Progress Software","product":"LoadMaster","versions":[{"status":"affected","version":"V7.2.60.0","lessThan":"V7.2.63.2","versionType":"custom"},{"status":"affected","version":"V7.2.45.12","lessThan":"V7.2.54.18","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"Progress Software","product":"ECS Connections Manager","versions":[{"status":"affected","version":"V7.2.60.0","lessThan":"V7.2.63.2","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"Progress Software","product":"Object Scale Connection Manager","versions":[{"status":"affected","version":"V7.2.60.0","lessThan":"V7.2.63.2","versionType":"custom"}],"defaultStatus":"unaffected"},{"vendor":"Progress Software","product":"MOVEit WAF","versions":[{"status":"affected","version":"V7.2.60.0","lessThan":"V7.2.63.2","versionType":"custom"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints","supportingMedia":[{"type":"text/html","base64":false,"value":"OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints"}]}],"references":[{"url":"https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691","tags":["vendor-advisory"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseSeverity":"CRITICAL","baseScore":9.6,"vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"}}],"workarounds":[{"lang":"en","value":"plain text","supportingMedia":[{"type":"text/html","base64":false,"value":"<div>html text</div>"}]}],"credits":[{"lang":"en","value":"Jacky Yang and Syed Ibrahim Ahmed of TrendAI Research","type":"finder"}],"source":{"discovery":"EXTERNAL"},"x_generator":{"engine":"Vulnogram 0.2.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-06-04T00:00:00+00:00","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3","id":"CVE-2026-8037"}}},{"other":{"type":"kev","content":{"dateAdded":"2026-08-07","reference":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-8037"}}}],"references":[{"url":"https://labs.watchtowr.com/enterprise-tech-in-shell-out-progress-kemp-loadmaster-uninitialized-heap-to-pre-auth-rce-cve-2026-8037/","tags":["third-party-advisory","exploit"]},{"url":"https://www.esentire.com/security-advisories/progress-kemp-loadmaster-vulnerability-targeted-cve-2026-8037","tags":["media-coverage"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-8037","tags":["government-resource"]}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-08-08T03:55:14.713Z"},"timeline":[{"time":"2026-08-07T00:00:00.000Z","lang":"en","value":"CVE-2026-8037 added to CISA KEV"}]}]}}