A security vulnerability has been identified in Progress LoadMaster, a tool some website operators use to balance traffic across their sites to maintain reliable, consistent service for visitors. This flaw is a command injection issue, meaning an attacker does not need valid login credentials for the system to exploit it. By targeting unsanitized input in multiple of LoadMaster's command endpoints, an unauthenticated attacker can run arbitrary, unauthorized commands directly on the LoadMaster appliance. If you use Progress LoadMaster to support your hosted website, this vulnerability could allow an attacker to take control of your load balancing system. This may result in disrupted access to your site, unauthorized access to data related to your hosted services, or other negative impacts to your online properties.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-8037