← Back to blog

Critical Progress Kemp LoadMaster Flaw Added to CISA KEV Catalog

A high-severity command injection vulnerability in Progress Kemp LoadMaster has been added to CISA's Known Exploited Vulnerabilities list after over 790 exploitation attempts were reported.

TL;DR

  • CVE-2026-8037 is a critical command injection flaw in Progress Kemp LoadMaster with a CVSS score of 9.6.
  • CISA has added the vulnerability to its KEV catalog due to active exploitation in the wild.
  • Over 792 exploit attempts have been reported, highlighting immediate risk to affected organizations.
  • Organizations using LoadMaster should prioritize patching or mitigation to prevent compromise.
  • The flaw enables attackers to execute arbitrary commands, potentially leading to full system control.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability affecting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog. Tracked as CVE-2026-8037, the flaw is a command injection issue that carries a high CVSS score of 9.6, making it a prime target for threat actors.

Reports indicate that the vulnerability is under active exploitation, with more than 792 attempted attacks recorded. This development underscores the urgency for organizations using LoadMaster to assess their exposure and apply necessary patches or mitigations immediately.

Given the severity and ongoing exploitation, this flaw represents a significant risk to enterprise infrastructure and warrants immediate attention from security teams.

Vulnerability Details

  • CVE-2026-8037 is a command injection vulnerability in Progress Kemp LoadMaster.
  • It has a CVSS score of 9.6, indicating critical severity.
  • The flaw allows unauthenticated attackers to inject and execute arbitrary commands.
  • Successful exploitation can lead to full system compromise and persistent access.
  • No authentication is required to exploit the vulnerability, increasing its threat potential.

Impact and Response

  • CISA added the flaw to its KEV catalog following evidence of active exploitation.
  • More than 792 exploitation attempts have been detected in the wild.
  • Organizations are advised to update LoadMaster installations to patched versions.
  • Network segmentation and monitoring can help reduce impact while applying fixes.
  • Security teams should audit logs for signs of exploitation related to CVE-2026-8037.

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.

Critical Progress Kemp LoadMaster Flaw Added to CISA KEV Catalog — Agent Breach Blog | Agent Breach