Progress LoadMaster patches RCE flaws
Progress LoadMaster and Connection Manager have vulnerabilities allowing remote code execution and security policy bypass; patches are available.
ANSSI (CERT-FR) issued an advisory detailing multiple vulnerabilities in Progress LoadMaster products, including Connection Manager for ObjectScale, ECS Connection Manager, and LoadMaster GA/LTFS. The flaws, tracked as CVE-2026-8037 and CVE-2026-33691, allow an attacker to achieve remote code execution and bypass security policy controls on affected versions prior to v7.2.63.2 (or v7.2.54.18 for LTFS).
Progress Software published a critical security bulletin on June 4, 2026 addressing these issues. No evidence of active exploitation is mentioned in the advisory; organizations running affected versions are advised to apply the vendor's patches promptly.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0883
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free