Critical 9.8 Actively Exploited

Progress ADC exploited for unauthenticated RCE (CVE-2026-8037) [PoC]

CVE-2026-8037

By Yazoul AI · automated

CVE-2026-8037: Progress ADC LoadMaster unauthenticated command injection RCE (CVSS 9.8), actively exploited. Apply vendor patch or restrict network access now.

Affected: Progress Connection Manager For Objectscale Progress Ecs Connection Manager Progress Loadmaster

Actively exploited in the wild - CVE-2026-8037 is a critical OS command injection flaw in Progress ADC LoadMaster that grants unauthenticated remote code execution on the appliance. Patches are available; update immediately and restrict adjacent network access.

Overview

CVE-2026-8037 is a pre-authentication OS command injection vulnerability affecting Progress Application Delivery Controller (ADC) products, including the LoadMaster appliance. The flaw resides in multiple command endpoints of the API, where unsanitized user input is passed directly to operating system commands. An attacker positioned on the adjacent network can exploit this without any credentials or user interaction, achieving full remote code execution with elevated privileges on the underlying appliance.

The vulnerability carries a CVSS score of 9.8 (Critical) with a low attack complexity, reflecting how easily it can be triggered. Critically, CISA has added CVE-2026-8037 to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in real-world environments. The EPSS model predicts an 84.8% probability of exploitation within 30 days, making this a top-priority threat for any organization running affected LoadMaster versions.

Impact

Successful exploitation grants the attacker arbitrary command execution as the LoadMaster service user, which typically runs with root or elevated privileges. This means full compromise of the ADC appliance, including:

  • Data exposure: Access to all traffic that passes through the LoadMaster, including TLS-terminated session data, credentials, and application payloads.
  • Lateral movement: The compromised appliance becomes a pivot point into the internal network, bypassing perimeter security controls.
  • Persistent backdoor: Attackers can install persistent malware, modify load-balancing rules, or redirect traffic to malicious endpoints.
  • Service disruption: The appliance can be taken offline, taking down every application and service behind it.

Remediation and Mitigation

Progress has released security patches addressing CVE-2026-8037. Organizations should take the following steps immediately:

  1. Apply vendor patches: Upgrade affected LoadMaster and ADC installations to the patched versions specified in the Progress security advisory. This is the only complete fix.
  2. Restrict network access: Where patching is not immediately possible, restrict access to the management API to trusted administrative networks only. Do not expose the API to untrusted segments.
  3. Audit for compromise: Assume breach if the appliance was exposed to adjacent networks. Review logs for anomalous API calls, unexpected command execution, or new administrative accounts.
  4. Monitor CISA KEV: Continue tracking CISA’s KEV catalog for updated indicators of compromise and detection guidance.

Security Insight

CVE-2026-8037 follows a disturbing pattern of enterprise network appliances becoming primary intrusion targets. Unlike server-side software that can be patched in minutes, ADCs and similar edge devices often run customized, minimally updated firmware where security fixes lag behind discovery. The combination of unauthenticated access and OS-level command execution in a device that sees all network traffic makes this class of vulnerability disproportionately damaging. Organizations should treat their ADC fleet as a crown-jewel asset, apply patches aggressively, and segment management interfaces away from general network traffic as a baseline security posture.

Further Reading

Share:

Never miss a critical vulnerability

Get real-time security alerts delivered to your preferred platform.

Public PoC References

Unverified third-party code

These repositories are publicly listed on GitHub and have not been audited by Yazoul Security. They may contain malware, backdoors, destructive payloads, or operational security risks (telemetry, exfiltration). Treat them as hostile binaries. Inspect source before execution. Run only in isolated, disposable lab environments (offline VM, no credentials, no production data).

Authorized use only. This information is provided for defensive research, detection engineering, and patch validation. Using exploit code against systems you do not own or do not have explicit written permission to test is illegal in most jurisdictions and violates Yazoul's terms of use.

Repository Stars
HORKimhab/CVE-2026-8037

CVE-2026-8037 - Draft

★ 0
Caster-chen/CVE-2026-8037-POC

包括能执行的命令探测和一键getshell(需要服务器部署服务)

★ 0

Showing 2 of 2 known references. Source: nomi-sec/PoC-in-GitHub.

Nuclei Detection Templates

Detection template available — your exposure is being scanned

The templates below are YAML signatures for the Nuclei scanner from ProjectDiscovery. They are not exploit code — they are detection rules that confirm whether a target is vulnerable. The presence of a Nuclei template means every bug bounty hunter, AppSec team, red team, and reconnaissance pipeline on the public internet is actively probing for this CVE.

Assume your exposed instances have already been touched. Patch immediately even if no exploitation is observed yet — fingerprinting precedes exploitation by days at most.

Template Source
CVE-2026-8037.yaml View YAML

1 Nuclei template indexed for this CVE. Source: projectdiscovery/nuclei-templates.

Related Advisories

Related Across Yazoul

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.