Progress LoadMaster: Progress LoadMaster Command Injection Vulnerability

  • Saturday, 8th August, 2026
  • 22:03pm

A security vulnerability has been identified in Progress LoadMaster, a tool many website operators use to distribute incoming traffic across multiple servers to improve site speed and reliability.

The flaw is a command injection issue. This means an attacker does not need any valid login credentials to exploit it: they can send specially crafted, unscreened input to multiple command features built into the LoadMaster software to run any arbitrary commands directly on the LoadMaster device.

If you use Progress LoadMaster to manage traffic for your website, a successful exploit could let an attacker take full control of your load balancer. This could be used to disrupt your site’s availability, intercept or steal data passing through the load balancer, or access other systems connected to your hosting environment.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-8037

« Back