This notice is for hosting clients who use Progress LoadMaster. A security flaw called a command injection vulnerability has been found in this tool.
This flaw lets an attacker who does not have any login access to the LoadMaster system run any commands they want directly on the LoadMaster appliance. The attacker can trigger this by sending specially crafted, unfiltered input to multiple command features of the tool.
If this vulnerability is exploited, an attacker could take full control of the LoadMaster appliance. This could lead to disruption of services tied to the appliance, unauthorized access to associated data, or the compromised system being used to target other infrastructure.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-8037