Multiple Vulnerabilities in Progress LoadMaster (July 15, 2026)
Multiple vulnerabilities have been discovered in Progress LoadMaster. They allow an attacker to cause remote arbitrary code execution and a security policy bypass.
CSIRTS triage
- What
- Multiple vulnerabilities could allow remote code execution and security policy bypass.
- Who is affected
- Users of Progress LoadMaster.
- Urgency
- Remediation is urgent due to the potential for exploitation.
- Action
- Users should apply the necessary updates to Progress LoadMaster.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch LoadMaster
Get an email when a new LoadMaster advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0883/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-8037Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 99.9% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-336913.6% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 88% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-8037 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-33691 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- criticalexploitedProgress security advisory (AV26-552) – Update 2cccs
- highexploitedCISA Adds One Known Exploited Vulnerability to Catalogcisa
- criticalexploitedCVE-2026-8037: Progress LoadMaster Command Injection Vulnerabilitycisa-kev
- critical[UPDATE] [critical] Kemp LoadMaster: Multiple vulnerabilitiescert-bund
Recent advisories for Progress LoadMaster
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- criticalexploitedCVE-2026-8037: Progress LoadMaster Command Injection Vulnerabilitycisa-kev · 2026-08-07
- high[NEW] [high] Progress Software LoadMaster and MOVEit WAF: Multiple vulnerabilitiescert-bund · 2026-07-28
- highCVE-2026-59690: A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager,…nvd · 2026-07-27
- highCVE-2026-59689: An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manag…nvd · 2026-07-27
- highCVE-2026-59688: An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager,…nvd · 2026-07-27
- highCVE-2026-59687: An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager,…nvd · 2026-07-27
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Elastic Kibana (August 14, 2026)2026-08-14
- unknownMultiple vulnerabilities in Netgate products (August 14, 2026)2026-08-14
- unknownMultiple vulnerabilities in SUSE Linux kernel (August 14, 2026)2026-08-14
- unknownMultiple vulnerabilities in Stormshield Network Security (August 14, 2026)2026-08-14
- unknownVulnerability in Sophos products (August 14, 2026)2026-08-14