FAIL › dossier
loadmaster
PRODUCT· dossier confidence 80%
LoadMaster ADC products have demonstrated a critical security posture with two confirmed unauthenticated RCE vulnerabilities (CVE-2026-8037, CVE-2024-1212) allowing arbitrary command execution.
PROFILE
CategoryProductWhat they doLoadMaster is a product line of Application Delivery Controllers (ADC) used for load balancing and traffic management.
SECURITY POSTURE
Critical vulnerabilities have been repeatedly exploited via unauthenticated remote code execution (RCE) in the management interface and API, indicating a high-risk security posture.
Notable failures
- CVE-2026-8037: Critical RCE via API Command Injection
- CVE-2024-1212: Critical RCE via Management Interface
- Repeated unpatched critical vulnerabilities in ADC products
Patterns: Repeated critical RCE vulnerabilities in management interfaces; Unauthenticated remote code execution in API endpoints
FAILURE HISTORY · 3
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-08-07 | CVE-2026-8037 | high | Progress LoadMaster appliances have a command injection vulnerability allowing unauthenticated attackers to execute arbitrary commands. |
| 2026-06-04 | CVE-2026-8037 | critical | OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints |
| 2024-02-21 | CVE-2024-1212 | critical | Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution. |
Open questions: Company identity and corporate structure · Current remediation status of CVE-2026-8037 · Third-party vendor status vs. independent product
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-31 03:55:41.473638+00:00