Progress bug can run code

Published August 7, 2026 CVE-2026-8037

The flaw affects Progress before 7.2.63.2 and can let an attacker run code on the affected system.

Severity
CriticalCVSS 3.1 ยท 9.6
Fix
Fixed in 7.2.63.2Fix recorded on Aug 26, 2026
Affected versions
V7.2.60.0 to before V7.2.63.2; V7.2.45.12 to before V7.2.54.18; V7.2.60.0 to before V7.2.63.2+2 more
Weakness
CWE-77Command Injection
Exploit likelihood
100% in 30 daysEPSS, higher than 100% of known flaws
Affects
LoadMaster+3 more
Exploited
Yes, in the wildListed by CISA
Added to CISA list
Aug 7, 2026
Federal fix deadline
Aug 10, 2026

How it works

Progress LoadMaster bug can run attacker commands OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.

What to do

Check the installed Progress version. This advisory applies to versions older than 7.2.63.2 or versions older than 7.2.54.18, and other affected versions.

Update Progress to 7.2.63.2 or 7.2.54.18 or newer. Then verify the installed version.

Technical details

Affected software: LoadMasterby Progress Software, ECS Connections Managerby Progress Software, Object Scale Connection Managerby Progress Software, MOVEit WAFby Progress Software

The source identifies Progress as the affected product. Affected ranges: before 7.2.63.2, before 7.2.54.18, 7.2.55 to before 7.2.63.2. Fixed versions: 7.2.63.2, 7.2.54.18.

Severity breakdown

  • Attack vector Adjacent Needs access to the same local network
  • Attack complexity Low Low complexity under the assessed conditions
  • Privileges required None Attacker needs no account or login
  • User interaction None No victim action needed
  • Scope Changed Impact crosses a security authority boundary
  • Confidentiality impact High Sensitive data can be exposed with serious impact
  • Integrity impact High Protected data can be changed with serious impact
  • Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Open in FIRST.org calculator