# Progress LoadMaster patches RCE flaws

Published: 2026-07-15 · Severity: high · Sectors: technology
Canonical: https://vorant.io/reports/ce77abe8-5467-5137-8a32-e3f025b95837/progress-loadmaster-patches-rce-flaws

> Progress LoadMaster and Connection Manager have vulnerabilities allowing remote code execution and security policy bypass; patches are available.

ANSSI (CERT-FR) issued an advisory detailing multiple vulnerabilities in Progress LoadMaster products, including Connection Manager for ObjectScale, ECS Connection Manager, and LoadMaster GA/LTFS. The flaws, tracked as CVE-2026-8037 and CVE-2026-33691, allow an attacker to achieve remote code execution and bypass security policy controls on affected versions prior to v7.2.63.2 (or v7.2.54.18 for LTFS).

Progress Software published a critical security bulletin on June 4, 2026 addressing these issues. No evidence of active exploitation is mentioned in the advisory; organizations running affected versions are advised to apply the vendor's patches promptly.

## Mentioned in this report

- Vulnerabilities: CVE-2026-33691, CVE-2026-8037 (templated)

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0883

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/ce77abe8-5467-5137-8a32-e3f025b95837/progress-loadmaster-patches-rce-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
