Database/Control plane, storage & DevOps

Progress LoadMaster (ADC): OS command injection in the API
CVSS 9.6CVE-2026-8037Control plane, storage & DevOpsKnown exploitedcurated
Impact
OS command injection in the API -> unauthenticated remote code execution on the load balancer
Who can reach it
Adjacent network
What to do
Control-plane: patch; the ADC terminates tenant-facing TLS
References
Related entries
- Vault Secrets Operator: tenant-controlled AppRole config reads operator pod files and exfiltrates themCVE-2026-8715 · HashiCorp Vault Secrets Operator (AppRole secretIDPath configuration)Critical
- Johnson Controls Metasys Application and Data Server (ADS) deployed with SQL Express: Command injection on the MetasysCVE-2025-26385 · Johnson Controls Metasys Application and Data Server (ADS) deployed with SQL ExpressCritical
- Citrix NetScaler ADC/Gateway: unauthenticated attacker executes arbitrary commands on the applianceCVE-2026-88771 · Citrix NetScaler ADC / Gateway (input validation in the management/authentication request path)Critical
- Citrix NetScaler ADC/Gateway: unauthenticated remote code execution or denial of serviceCVE-2026-88772 · Citrix NetScaler ADC / GatewayCritical
- CyberPower PowerPanel Business Local/Remote/Management v4.8.6 and earlier (Windows and Linux): A default passwordCVE-2023-25131 · CyberPower PowerPanel Business Local/Remote/Management v4.8.6 and earlier (Windows and Linux)Critical
- Grafana: Azure AD accounts validated on the mutable, non-unique email claimCVE-2023-3128 · GrafanaCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.