CISA warns of active Progress LoadMaster vulnerability exploitation
TL;DR. CISA issued a warning that hackers are actively exploiting a critical command injection vulnerability in Progress Kemp LoadMaster devices. - The flaw, CVE-2026-8037, allows unauthenticated attackers to execute arbitrary commands on vulnerable appliances. - Kemp LoadMaster is a widely used Application Delivery Controller by tech companies and government entities globally. - CISA mandated federal agencies to patch their servers within three days, urging all organizations to prioritize updates.
- CISA warns of active exploitation of CVE-2026-8037 in Progress Kemp LoadMaster.
- The critical command injection vulnerability allows arbitrary command execution.
- Progress Software released patches in June for affected LoadMaster and MOVEit WAF versions.
- CISA ordered U.S. Federal Civilian Executive Branch agencies to patch within three days.
Sources
- Critical Progress LoadMaster flaw now actively exploited in attacks — bleepingcomputer.com
- securityweek.com — securityweek.com