Critical OS Command Injection RCE (CVE‑2026‑8037) in Progress LoadMaster Added to CISA KEV Catalog
What It Is — A remote‑code‑execution flaw (CVE‑2026‑8037) in the API layer of Progress LoadMaster (ADC) appliances allows an unauthenticated attacker to inject OS commands via unsanitized input.
Exploitability — CVSS 9.6 (Critical). Public PoC released 29 June 2026; eSentire observed exploitation attempts beginning 29 June, though no successful post‑compromise activity has been confirmed.
Affected Products — Progress LoadMaster (all versions prior to the vendor‑released patch).
Why It Matters for Compliance & Audit Readiness
- Control Mapping – The flaw maps to SOC 2 CC6.1 (System Operations) and CC7.1 (Change Management); evidence of timely patching is a core audit artifact.
- Continuous Evidence – Demonstrating that you have a process to detect, assess, and remediate high‑severity vulnerabilities satisfies the “risk mitigation” narrative demanded by auditors and enterprise buyers.
- Defensible Audit Trail – Capturing patch‑deployment logs, vulnerability‑scan results, and remediation tickets provides the immutable proof required for a successful SOC 2 audit.
Recommended Actions
- Apply the vendor‑released security patch to all LoadMaster appliances immediately.
- Update your asset inventory and tag the LoadMaster instances with the CVE identifier.
- Run an authenticated scan to verify remediation and capture scan reports as audit evidence.
- Map the remediation activity to SOC 2 CC6.1/CC7.1 controls in your compliance framework.
- Enable continuous monitoring of the LoadMaster API endpoints for anomalous command‑injection patterns.
Source: SecurityAffairs article