A security vulnerability has been identified in Progress LoadMaster, a tool some websites use to balance traffic across servers to keep sites running reliably during high visitor volume. This flaw only affects users of this specific tool, and does not impact other common hosting services or software.
The vulnerability allows unauthenticated attackers (people without approved login access to your LoadMaster system) to run arbitrary, unauthorized commands on the LoadMaster appliance. Bad actors can exploit this by sending unsanitized input to multiple command endpoints on the tool.
If successfully exploited, this could let attackers disrupt your site's traffic routing, interfere with normal website operations for your visitors, or access sensitive data connected to the LoadMaster system.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-8037