A security vulnerability has been identified in Progress LoadMaster, a load balancing tool some website owners use to distribute traffic across multiple servers for improved reliability and performance.
This is a command injection flaw, meaning attackers who do not have any authorized access to a LoadMaster system can send specially crafted, unsanitized input to specific command endpoints on the device to run arbitrary unauthorized commands directly on the LoadMaster appliance.
If your hosting setup uses Progress LoadMaster to manage your website's traffic, this vulnerability could allow bad actors to take control of the load balancer device. This may lead to unexpected service disruptions for your website, as attackers could run commands that interfere with the device's normal operation.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-8037