Progress LoadMaster: Progress LoadMaster Command Injection Vulnerability

  • Monday, 10th August, 2026
  • 22:04pm

A security vulnerability has been identified in Progress LoadMaster, a tool many hosting clients use to manage traffic and uptime for their websites. This flaw is a command injection issue, a type of security gap that can allow unauthorized users to run code on a system.

The vulnerability lets an attacker with no valid login credentials for the LoadMaster appliance execute arbitrary, unauthorized commands directly on the system. This is possible because the LoadMaster does not properly filter user input sent to several of its command features, allowing malicious input to trigger the unwanted command execution.

Since LoadMaster is used to route and manage traffic for the websites it supports, a successful exploit of this flaw could potentially impact the performance, availability, or security of any websites configured to use the affected LoadMaster instance.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-8037

« Back