A security vulnerability has been identified in Progress LoadMaster, a tool used to distribute web traffic across servers to keep websites running reliably. This flaw is a command injection issue, meaning attackers can exploit unsanitized input sent to multiple command endpoints of the LoadMaster system to trigger unintended actions.
This vulnerability is especially serious because it can be exploited by unauthenticated users, meaning attackers do not need any valid login credentials to carry out an attack. A successful exploit would let an unauthorized person run any arbitrary commands directly on the LoadMaster appliance itself.
For clients using LoadMaster to manage traffic to your websites, this flaw means the load balancing system supporting your site could be fully controlled by an unauthorized attacker if the vulnerability is successfully exploited.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-8037