Progress Software has released a security update to address a product vulnerability.
The vulnerability is CVE-2026-8037, a remote code execution vulnerability caused by OS command injection in the API of the Progress ADC product.
The affected products and versions are as follows:
Progress Kemp LoadMaster GA version 7.2.63.1 And earlier.
Progress Kemp LoadMaster LTSF version 7.2.54.17 And earlier.
Progress ECS Connection Manager version 7.2.63.1 And earlier.
Progress Connection Manager for ObjectScale version 7.2.63.1 Or earlier.
Progress MOVEit WAF GA version 7.2.63.1 Or earlier.
A Vulnerability Patch has been released via the latest update.
The versions as follows are considered secure after the update:
Progress Kemp LoadMaster GA version 7.2.63.2 Or later.
Progress Kemp LoadMaster LTSF version 7.2.54.18 Or later.
Progress ECS Connection Manager version 7.2.63.2 Or later.
Progress Connection Manager for ObjectScale version 7.2.63.2 Or later.
Progress MOVEit WAF GA version 7.2.63.2 Or higher.
For reference, see the LoadMaster Critical Security Bulletin – June 2026 – (CVE-2026-8037, CVE-2026-33691) and the MOVEit WAF Critical Security Bulletin – June 2026 – (CVE-2026-8037, CVE-2026-33691) were provided as reference materials.