A command injection vulnerability has been identified in Progress LoadMaster. This flaw allows unauthenticated attackers, meaning anyone without a valid login for the system, to run any arbitrary commands they want directly on the LoadMaster appliance. The vulnerability exists because the system does not properly filter unsanitized input sent to multiple of its command processing endpoints.
For hosting customers who use Progress LoadMaster to support their websites, this creates potential security risks. A bad actor could exploit this flaw to disrupt your site's availability, make unauthorized changes to how your site is delivered to visitors, or access data associated with your hosted services.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-8037