A security flaw has been identified in Progress LoadMaster, a tool used to balance web traffic and keep online services available. This is a command injection vulnerability: unsafe, unscreened input sent to multiple command-handling parts of the tool can be exploited by attackers.
The flaw is especially serious because no login or access credentials are required to exploit it. An attacker who takes advantage of this flaw can run any unrestricted commands directly on the LoadMaster appliance. For users of this tool, this creates risk of service disruptions, unauthorized access to data associated with the appliance, or the compromised system being used for other malicious activity.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-8037