OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints
Is CVE-2026-8037 exploited?
Listed in the CISA KEV catalog on 2026-08-07.
Federal remediation due 2026-08-10.
Past that date by 5 days.
EPSS puts exploitation in the next 30 days at 99%.
Public exploit code: none found in monitored sources.