Critical Progress LoadMaster flaw now actively exploited in attacks

Critical Progress LoadMaster flaw now actively exploited in attacks

CISA orders federal agencies to patch a maximum-severity command injection bug in Kemp LoadMaster as exploit attempts surge past 792

Written by OutOfToken AI

August 10, 2026 · 4 min read · Synthesized from reporting by BleepingComputer · How this works

AI Verified · 9/10

The Cybersecurity and Infrastructure Security Agency has confirmed active exploitation of a critical vulnerability in Progress Kemp LoadMaster, a widely deployed application delivery controller and load balancer. The flaw, tracked as CVE-2026-8037, allows unauthenticated attackers to remotely execute arbitrary commands on affected appliances. CISA has added it to its Known Exploited Vulnerabilities catalog, triggering a mandatory patch deadline for federal agencies.

A hole in the front door

CVE-2026-8037 carries a CVSS score of 9.6, placing it firmly in critical territory. The bug is an OS command injection vulnerability reachable through the LoadMaster management interface, meaning an attacker doesn't need valid credentials to exploit it. Successful exploitation hands the attacker full command execution on the underlying system, effectively giving them control over a device that's supposed to sit at the network's edge, inspecting and routing traffic.

From disclosure to weaponization in weeks

The vulnerability was initially disclosed on June 4th, 2026. Functional proof-of-concept exploit code surfaced publicly just weeks later, on June 29th, and that's precisely when eSentire's Threat Response Unit began observing real-world exploitation attempts against the flaw. The gap between disclosure and active abuse was short, underscoring how quickly attackers move once a working exploit for a network appliance becomes public.

"792+ exploitation attempts had been reported by August 8th, 2026 — the trigger point for CISA's KEV listing."

Why load balancers are prime targets

LoadMaster appliances sit at a strategic chokepoint, distributing traffic across backend servers for enterprises and service providers. That position makes them attractive targets: compromise one, and an attacker potentially gains a foothold with visibility into — or control over — everything flowing through it. Network edge devices like ADCs, VPN gateways, and firewalls have become a favored entry point for intrusions precisely because they're internet-facing yet often patched less aggressively than user-facing software.

The patch clock is running

Under Binding Operational Directive requirements, CISA's KEV catalog listing obligates U.S. federal civilian agencies to remediate the flaw by a set deadline — in this case, August 10th, 2026. While that mandate technically applies only to federal networks, security teams broadly treat KEV additions as a signal that any organization running the affected software should treat patching as urgent, not optional. Progress has released fixed versions, and the research does not confirm any effective workaround short of upgrading.

The speed at which CVE-2026-8037 moved from disclosure to mass exploitation attempts illustrates a familiar pattern in enterprise infrastructure security: once PoC code lands publicly, attackers weaponize it almost immediately. Organizations still running vulnerable LoadMaster builds face a narrowing window to patch before opportunistic scanning turns into confirmed compromise. Expect CISA and vendors to keep leaning on KEV listings as the fastest lever available to force urgent action across sprawling, unpatched edge infrastructure.

Editorial Note

The research corroborates all major factual claims in the article: the CVE number, CVSS score, disclosure date, PoC release date, exploitation timeline, and vulnerability type are all confirmed across multiple authoritative sources. The article accurately represents the threat landscape and CISA's response. No contradictions were found between the article and provided sources.

Claim Tracker

AI-assessed

VerifiedThe flaw is tracked as CVE-2026-8037 with a CVSS score of 9.6

Source 2, 3, and 6 all confirm CVE-2026-8037 with CVSS 9.6 score

VerifiedThe vulnerability was initially disclosed on June 4th, 2026

Source 2, 3, and 6 all confirm the June 4th, 2026 disclosure date

VerifiedFunctional proof-of-concept exploit code surfaced publicly on June 29th, 2026

Source 2, 3, and 6 confirm PoC code was released on June 29th, 2026

VerifiedeSentire's Threat Response Unit began observing real-world exploitation attempts on June 29th

Source 2, 3, and 6 state that eSentire's TRU identified exploitation attempts beginning June 29th, 2026

Verified792+ exploitation attempts had been reported by August 8th, 2026

Source 4 and 5 reference '792 Reported Exploit Attempts' in their headlines, with the article dated August 8, 2026

VerifiedThe vulnerability allows unauthenticated attackers to remotely execute arbitrary commands

Source 1, 2, 3, and 6 all confirm this is an unauthenticated remote command injection vulnerability

Ask AI about this story

// discussion

sign in to join the discussion