Unauthenticated command injection in LoadMaster management endpoints
Progress · LoadMaster
Confirmed exploitation, pre-authentication access and direct command execution on a perimeter appliance.
What, why & how
A command-injection flaw in the LoadMaster administration plane.
The vulnerable input crosses into a system command without sufficient validation, turning a web request into appliance-level code execution.
An unauthenticated attacker sends crafted input to an exposed management endpoint. Successful execution can lead to full appliance compromise.
Exploit reality
CISA added this CVE to KEV on 7 August 2026, confirming evidence of active exploitation.
Exploit mechanics have been publicly demonstrated. Treat scanning and exploit traffic as credible, not theoretical.
Internet-facing management plane → command injection → appliance takeover → credential theft or traffic interception
After exploitation, built-in shell and network utilities may be used for discovery, persistence and movement without dropping a large toolset.
Patch & workaround
- Affected
- LoadMaster releases listed in the Progress June 2026 critical security bulletin.
- Fixed
- See Progress security bulletin for the fixed release matching your branch.
- Action
- Apply the current Progress LoadMaster security update and follow the vendor's compromise-assessment steps.
- Workaround
- If the update cannot be applied immediately, remove the management interface from untrusted networks and restrict access to a trusted administration segment.
Evidence & provenance
Last reviewed 10 Aug 2026, 16:19 UTC · CWE-77 · Command Injection
