AL
Analyst accessPublic view · sign in

Vulnerability threat dossier

CVE-2026-8037

progressconnection manager for objectscale

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints

VTP deterministic threat58.4of 100 · CVSS excluded

VTP analyst assessment

No AI candidate assessment for this subject

AI-assisted analytical recommendationDoes not set factual exploitation state
AI classificationNO ALERT
AI priorityNONE
AI confidenceUnknown
Public exploitation · VTP factKEV

Assessment

The latest persisted AI review did not propose this CVE for analyst escalation. Deterministic monitoring remains authoritative for the factual states below.

Why it matters

Unknown from persisted AI analysis.

Evidence

No AI candidate evidence set is persisted for this CVE.

Uncertainties

No first-party sensor telemetry is configured. Local exploitation observation is unknown.

Next watchpoint · deterministic

A validated functional exploit or automated exploitation capability would materially change this assessment.

AI analysis history (0)
    Technical severityCRITICALCVSS 9.6 · technical context
    Public exploitationKEVGlobal public evidence
    Exploit maturityTECHNICAL DETAILSReliability not implied
    EPSS0.99100th percentile · prediction
    Evidence confidence60%Strongest independent active claim
    VelocitySTABLEMaterial events only
    First-party telemetryNo first-party sensor telemetry configured.
    Availability: NO_SENSOR_CONFIGURED · Evidence: UNKNOWN
    01

    VTP deterministic assessment

    Why this matters

    1. 01

      CISA KEV lists this vulnerability as known to be exploited globally.

    2. 02

      EPSS is 0.99; this is predictive context, not exploitation evidence.

    3. 03

      No first-party sensor telemetry is configured; first-party observation is unknown.

    02

    Material change ledger

    What changed

    KEV ADDEDCISA KEV entry added
    03

    Claim provenance

    Evidence and source independence

    2publications detected
    2underlying evidence chains

    0 primary sources · 0 dependent secondary reports · 2 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

    Source claimEXPLOITATION REPORTEDPUBLICATION REPORTS EXPLOITATION
    60%claim confidence
    UNKNOWNreport:57dca9b97e2e2c95798e881ff1b2ad0e9b487dd72db72642cdd2b5c065f81d5bACTIVE
    Evidence
    04

    Event history

    Threat timeline

    1. 06:5208 Aug
      EXPLOITATION REPORTED

      Exploitation Reported

      The Hacker News supplied a deterministically extracted signal; review the linked evidence before escalation.

    2. 00:0007 Aug
      KEV ADDED

      CISA KEV entry added

      CISA lists global known exploitation. This is not a VTP sensor observation.

    3. 18:5516 Jul
      EXPLOIT SOURCE UPDATE

      New exploit-source update

      ProjectDiscovery Nuclei Templates Releases published evidence linked to CVE-2026-8037.

    05

    Original publications

    Source record

    Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. The vulnerability, tracked as CVE-2026-8037 (CVSS score: 9.6), is a command injection flaw that could be weaponized to achieve arbitrary

    CVE-2026-8037
    Separate evidence group
    Original

    Nuclei Templates v10.4.6 - Release Notes

    New Templates Added: 74 | CVEs Added: 23 | First-time contributions: 6 🔥 Release Highlights 🔥 [ CVE-2026-52815 ] Gogs < 0.14.3 - Unauth Organization Teams Disclosure (@0x_Akoko) [low] 🔥 [ CVE-2026-50229 ] Apache Tomcat - Cross-Site Scripting (@yshahinzadeh, @AmirMSafari ) [medium] 🔥 [ CVE-2026-48611 ] phpBB < 3.3.17 - Auth Bypass ( @aikido , @dhiyaneshdk ) [critical] 🔥 [ CVE-2026-48313 ] ColdFusion - Path Traversal ( @watchtowr , @dhiyaneshdk ) [high] 🔥 [ CVE-2026-48282 ] Adobe ColdFusion - RDS Arbitrary File Write ( @watchtowr , @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [CVE-2026-44381] MISP < 2.5.37 - SQL Injection ( @malcha ) [medium] 🔥 [CVE-2026-28496] FOSSBilling - Server-Side Template Injection ( @dhiyaneshdk ) [critical] (vKEV) 🔥 [ CVE-2026-24207 ] NVIDIA Triton Inference Server <= 26.02 - Auth Bypass ( @VixianSchool ) [critical] 🔥 [ CVE-2026-22778 ] vLLM 0.8.3 - 0.14.0 - Information Disclosure ( @kenlacroix ) [critical] 🔥 [ CVE-2026-13731 ] WPBot <= 8.4.9 - Cross-Site Scripting (@0x_Akoko) [high] (vKEV) 🔥 [ CVE-2026-8386 ] WP Go Maps < 10.0.10 - Unauth Marker Information Disclosure (@0x_Akoko) [medium] 🔥 [ CVE-2026-8383 ] LearnPress < 4.3.7 - Information Disclosure (@0x_Akoko) [medium] 🔥 [ CVE-2026-8037 ] Progress ADC LoadMaster - Command Injection ( @watchtowr , @dhiyaneshdk ) [critical] (vKEV) 🔥 [ CVE-2026-3326 ] XStore Theme < 9.7.3 - SQL Injection ( @VixianSchool ) [high] 🔥 [ CVE-2026-1890 ] LeadConnector < 3.0.22 - Unauth Arbitrary Data Write (@0x_Akoko) [medium] (vKEV) 🔥 [ CVE-2025-29635 ] D-Link DIR-823X set_prohibiting - Command Injection ( @pussycat0x ) [high] (kev) (vKEV) 🔥 What's Changed Bug Fixes Fixed invalid matcher type in CVE-2025-29635 (PR #16506 ). Corrected incorrect delay seconds in the time-based SQL injection check (PR #16469 ). Fixed typo in tags from 'okiko' to 'okiok' (PR #16425 ). Corrected severity and description in concrete5-installer.yaml (PR #16523 ). Updated GitHub Pages takeover detection templates to reflect the new GitHub policy (Issue #10514 ). Fixed checksum generation ordering so it runs after template signing completes (PR #16450 ). Removed duplicate and obsolete templates: Tomcat exposed-panels duplicates (PR #16530 ), mikrotik-routeros-old.yaml (PR #16527 ), and 3dprint-arbitrary-file-upload.yaml (PR #16426 ). Corrected template names and file paths across a set of templates — nuuo-network-login (PR #16547 ), fuji-xerox-internet-service (PR #16546 ), trino-unauth-cluster (PR #16560 ), echo-detect (PR #16559 ), XOOPS installer (PR #16531 ), osticket-installer (PR #16529 ), zoneminder-system-log (PR #16498 ), unauth-opcache-control-panel (PR #16424 ), fortiadc-panel (PR #16525 ), Checkmarx panel (PR #16519 ), Cisco TelePresence MCU / ServiceGrid / ACE 4710 panels (PRs #16522 , #16521 , #16520 ), Avaya Aura System Manager and Communication Manager panels (PRs #16518 , #16517 ), joomla-com-fabrik-lfi (PR #16549 ), CVE-2016-9299 (PR #16548 ), and CVE-2025-47188 (PR #16433 ). False Negatives Fixed regex in CVE-2026-1731 that failed on targets returning company instead of default_company (PR #16545 , Issue #16544 ). Extended the Spring Boot heap dump template to cover additional BBO endpoints, catching instances previously missed (PR #16503 , Issue #11653 ). Added more selectors to dkim-record-detect.yaml to reduce missed records (PR #16535 ). Added additional Keycloak admin panel paths (PR #16495 , Issue #16376 ). Added another Spring Boot Actuator HTTP path (PR #16571 ). False Positives Reduced false positives and improved accuracy in the following templates: CVE-2024-37881 — excluded multiple WordPress endpoints and generic redirects (PRs #16494 , #16504 , Issue #16423 ) CVE-2024-34351 — corrected wrong detection (PR #16500 , Issue #11641 ) Time-based SQL injection detection (PR #16510 ) Casbin MCP Gateway default login (PR #16477 ) dns/caa — now matches only the ANSWER section (PR #16453 ) apache-mod-negotiation-listing.yaml - incorrect severity (Issue #16

    CVE-2010-4282CVE-2016-9299CVE-2019-5544CVE-2024-34351CVE-2024-37881CVE-2025-29635CVE-2025-47188CVE-2026-10823CVE-2026-13731CVE-2026-1731CVE-2026-1890CVE-2026-22778CVE-2026-24207CVE-2026-28496CVE-2026-30958CVE-2026-3326CVE-2026-34413CVE-2026-44381CVE-2026-46339CVE-2026-48282CVE-2026-48313CVE-2026-48611CVE-2026-50229CVE-2026-50751CVE-2026-52774CVE-2026-52815CVE-2026-56782CVE-2026-59801CVE-2026-8037CVE-2026-8383CVE-2026-8386
    Separate evidence group
    Original
    06

    Technical vulnerability data

    Context, not threat proof

    VTP threat score58.4vtp-threat-v1-public
    Public exploitation30 / 30
    EPSS prediction19.86 / 20
    Exploit availability2.5 / 15
    Source independence0 / 15
    Intelligence recency6 / 10
    Threat acceleration0 / 10
    CVSS technical severityExcluded
    CVSS
    9.6 · CRITICAL
    Vector
    CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
    CWE
    CWE-77
    CPE records
    4
    Deterministic history records
    5
    Primary technical reference
    07

    Raw observations

    First-party sensor records

    No first-party sensor telemetry configured.