A security flaw has been identified in Progress LoadMaster, a tool many websites use to balance incoming traffic across servers to keep sites running smoothly. The issue is a command injection vulnerability, which means the system does not properly check or filter input sent to multiple of its command-handling features.
This vulnerability can be exploited by attackers who do not need any existing login credentials or prior access to the LoadMaster system. If taken advantage of, an attacker can run any arbitrary commands on the LoadMaster appliance itself. For anyone using this tool to support their website, this could let bad actors disrupt your site's traffic flow, access sensitive data passing through the load balancer, or take full control of the system that manages your site's traffic.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-8037