CVE-2026-8037

CRITICAL EXPLOITED NUCLEI

Progress ADC Products - Unauthenticated OS Command Injection

Title source: manual
STIX 2.1

Exploitation Summary

CVE-2026-8037 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 2 public exploits from researchers including Caster-chen, HORKimhab. A Nuclei detection template is also available.

AI-analyzed exploit summary This PoC exploits CVE-2026-8037, an uninitialized heap memory vulnerability in Progress Kemp LoadMaster, to achieve pre-authentication remote command execution. The exploit uses a crafted JSON payload with malformed `apiuser` and heap spraying to inject commands via unterminated strings, which are then executed by the system() function.

Description

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints

Exploits (2)

github WORKING POC
by Caster-chen · remote
https://github.com/Caster-chen/CVE-2026-8037-POC

This PoC exploits CVE-2026-8037, an uninitialized heap memory vulnerability in Progress Kemp LoadMaster, to achieve pre-authentication remote command execution. The exploit uses a crafted JSON payload with malformed `apiuser` and heap spraying to inject commands via unterminated strings, which are then executed by the system() function.

Classification
Working Poc 98%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Progress Kemp LoadMaster (versions prior to GA v7.2.63.2 or LTSF v7.2.54.18+)
No auth needed
Prerequisites: Network access to the LoadMaster appliance's `/accessv2` endpoint · Python environment with `requests` library for the exploit script
mistral-large-3 · analyzed Jul 09, 2026 Full analysis →
github SUSPICIOUS
by HORKimhab · poc
https://github.com/HORKimhab/CVE-2026-8037

The repository lacks actual exploit code or technical details about CVE-2026-8037, instead providing generic setup instructions and a script to download external content. The README is filled with legal disclaimers but no vulnerability analysis.

Classification
Suspicious 90%
Attack Type
Other
Complexity
Theoretical
Reliability
Theoretical
Target: unspecified
No auth needed
Prerequisites: none specified
mistral-large-3 · analyzed Jun 30, 2026 Full analysis →

Nuclei Templates (1)

Progress ADC LoadMaster - Command Injection
CRITICALby watchtowr,DhiyaneshDk
FOFA: body="Progress" && icon_hash=="-2107233094"

Scores

CVSS v3 9.6
EPSS 0.8479
EPSS Percentile 99.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

VulnCheck KEV 2026-07-01
CWE
CWE-77
Status published
Products (8)
progress/connection_manager_for_objectscale < 7.2.63.2
progress/ecs_connection_manager < 7.2.63.2
progress/loadmaster < 7.2.54.18
Progress Software/ECS Connections Manager V7.2.60.0 - V7.2.63.2
Progress Software/LoadMaster V7.2.45.12 - V7.2.54.18
Progress Software/LoadMaster V7.2.60.0 - V7.2.63.2
Progress Software/MOVEit WAF V7.2.60.0 - V7.2.63.2
Progress Software/Object Scale Connection Manager V7.2.60.0 - V7.2.63.2
Published Jun 04, 2026
Tracked Since Jun 04, 2026