CVE-2026-8037
CRITICAL EXPLOITED NUCLEIProgress ADC Products - Unauthenticated OS Command Injection
Title source: manualExploitation Summary
CVE-2026-8037 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 2 public exploits from researchers including Caster-chen, HORKimhab. A Nuclei detection template is also available.
AI-analyzed exploit summary This PoC exploits CVE-2026-8037, an uninitialized heap memory vulnerability in Progress Kemp LoadMaster, to achieve pre-authentication remote command execution. The exploit uses a crafted JSON payload with malformed `apiuser` and heap spraying to inject commands via unterminated strings, which are then executed by the system() function.
Description
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints
Exploits (2)
This PoC exploits CVE-2026-8037, an uninitialized heap memory vulnerability in Progress Kemp LoadMaster, to achieve pre-authentication remote command execution. The exploit uses a crafted JSON payload with malformed `apiuser` and heap spraying to inject commands via unterminated strings, which are then executed by the system() function.
The repository lacks actual exploit code or technical details about CVE-2026-8037, instead providing generic setup instructions and a script to download external content. The README is filled with legal disclaimers but no vulnerability analysis.
Nuclei Templates (1)
body="Progress" && icon_hash=="-2107233094"
References (2)
Scores
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H