Skip to main content

Progress LoadMaster Command Injection Under Active Mass Exploitation from 792 Attack IPs (CVE-2026-8037)

Scope: Progress LoadMaster (All Versions Prior to GA 7.2.63.2 and LTSF 7.2.54.18)

Severity: Red

Over 792 unique IP addresses from 65 countries are actively scanning and exploiting CVE-2026-8037, a critical command injection vulnerability across multiple API endpoints in Progress LoadMaster, the widely deployed application delivery controller and load balancer that sits at the network edge in front of enterprise web services and critical internal applications. The unauthenticated attack surface and the volume of active exploitation infrastructure confirm this is now a mass exploitation campaign rather than targeted activity. Organizations running Progress LoadMaster must upgrade to LoadMaster GA 7.2.63.2 or LTSF 7.2.54.18 immediately, restrict management interface and API access from the internet entirely, and conduct a compromise assessment on any instance that was internet-exposed prior to patching given the confirmed exploitation activity.

The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.