Progress LoadMaster: Progress LoadMaster Command Injection Vulnerability

  • Sunday, 9th August, 2026
  • 16:03pm

A security flaw has been found in Progress LoadMaster, a load balancing tool some customers use to distribute traffic to their websites and online services. This is a command injection vulnerability. It means an attacker does not need any valid login or access credentials to run custom commands directly on the LoadMaster device, by sending specially crafted, unsanitized input to a number of the tool's command features. If you use Progress LoadMaster as part of your hosting environment, this issue could let unauthorized parties take control of the LoadMaster appliance, which may disrupt your services or put data tied to your setup at risk.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-8037

« Back