A critical-severity vulnerability in Progress Kemp LoadMaster, tracked as CVE-2026-8037, has been added to the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities catalog after 792 reported exploit attempts. This command injection flaw, with a CVSS score of 9.6, can be exploited to achieve arbitrary code execution. The vulnerability's inclusion in the KEV catalog indicates that it is being actively exploited in the wild, prompting CISA to urge affected parties to take immediate action1. The high CVSS score and active exploitation efforts suggest that this vulnerability poses a significant risk to organizations using the affected LoadMaster product. As a result, practitioners should prioritize patching or monitoring their systems to prevent potential attacks, given the vulnerability's potential for severe impact.
Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts
⚠️ Critical Alert
Why This Matters
CVE-2026-8037 is in active discussion involving CISA — exploitation status determines whether this is patch-now or monitor.
References
- The Hacker News. (2026, August 8). Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts. *The Hacker News*. https://thehackernews.com/2026/08/progress-kemp-loadmaster-flaw-hits-cisa.html
Original Source
The Hacker News
Read original →