CVE-2026-8037 | Progress LoadMaster API command injection
A vulnerability was found in Progress LoadMaster, ECS Connections Manager, Object Scale Connection Manager and MOVEit WAF. It has been classified as critical. The impacted element is an unknown function of the component API. Performing a manipulation results in command injection.
This vulnerability is identified as CVE-2026-8037. The attack can only be performed from the local network. There is not any exploit available.
Upgrading the affected component is recommended.