Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. The vulnerability, tracked as CVE-2026-8037 (CVSS score: 9.6), is a command injection flaw that could be weaponized to achieve arbitrary

Written by OutOfToken AI

August 10, 2026 · 3 min read · Synthesized from reporting by The Hacker News · How this works

AI Verified · 9/10

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. The vulnerability, tracked as CVE-2026-8037 (CVSS score: 9.6), is a command injection flaw that could be weaponized to achieve arbitrary

This story is developing. Follow OutOfToken for updates.

Editorial Note

All major factual claims in the article are directly corroborated by multiple research sources, particularly The Hacker News and official CISA references. The sources confirm the CVE identifier, CVSS score, vulnerability type, exploit count, and severity designation. No contradictions were found between the article and the research provided.

Claim Tracker

AI-assessed

VerifiedCISA added CVE-2026-8037 to its Known Exploited Vulnerabilities (KEV) catalog on Friday

Confirmed by Source 1 (Petronella Technology Group), Source 4 (Instagram/invulnernews), and Source 6 (Mallory aggregation citing Aug 7-8, 2026 dates)

VerifiedCVE-2026-8037 has a CVSS score of 9.6

Confirmed by Source 4 (invulnernews Instagram post) and Source 5 (Instagram post)

VerifiedThe vulnerability is a command injection flaw in Progress Kemp LoadMaster

Confirmed by Source 2 and Source 3 (The Hacker News): 'Progress LoadMaster contains a command injection vulnerability'

Verified792 reported exploit attempts were recorded

Confirmed by Source 1 (Petronella Technology Group), Source 4 (invulnernews), and Source 5 (invulnernews)

VerifiedThe flaw allows unauthenticated attackers to execute arbitrary commands

Confirmed by Source 2 and Source 3 (The Hacker News): 'allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance'

Ask AI about this story

// discussion

sign in to join the discussion