OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints
https://thehackernews.com/2026/08/progress-kemp-loadmaster-flaw-hits-cisa.html
https://thehackernews.com/2026/07/latest-progress-kemp-loadmaster-pre.html
https://thehackernews.com/2026/06/progress-kemp-loadmaster-flaw-could-let.html
Published: 2026-06-04
Updated: 2026-10-01
Known Exploited Vulnerability (KEV)
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 9.8
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: Critical
EPSS: 0.77362
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability of Interest