VORANT. Threat Intelligence Sign in Get the full feed

Progress LoadMaster patches RCE flaws

high vulnerability technology

Progress LoadMaster and Connection Manager have vulnerabilities allowing remote code execution and security policy bypass; patches are available.

ANSSI (CERT-FR) issued an advisory detailing multiple vulnerabilities in Progress LoadMaster products, including Connection Manager for ObjectScale, ECS Connection Manager, and LoadMaster GA/LTFS. The flaws, tracked as CVE-2026-8037 and CVE-2026-33691, allow an attacker to achieve remote code execution and bypass security policy controls on affected versions prior to v7.2.63.2 (or v7.2.54.18 for LTFS).

Progress Software published a critical security bulletin on June 4, 2026 addressing these issues. No evidence of active exploitation is mentioned in the advisory; organizations running affected versions are advised to apply the vendor's patches promptly.

Mentioned in this report

Vulnerabilities CVE-2026-33691CVE-2026-8037templated

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0883

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free