Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

Summary

CISA has added a critical severity flaw in Progress Kemp LoadMaster to its Known Exploited Vulnerabilities catalog. The vulnerability, CVE-2026-8037, is a command injection flaw that has reportedly been exploited in the wild over 790 times.

IFF Assessment

FOE

The addition of this vulnerability to CISA's KEV catalog and reports of widespread exploitation indicate active threats against systems using Progress Kemp LoadMaster, posing a risk to defenders.

Severity

9.6 Critical

CISA KEV: Listed as actively exploited. Federal patch due: August 10, 2026. Known ransomware use: Unknown.

Defender Context

This vulnerability affects Progress Kemp LoadMaster devices, which are often used for load balancing and application delivery. Defenders should prioritize patching or mitigating this vulnerability immediately, as it is being actively exploited and has been added to CISA's KEV catalog, meaning it is a known threat.

Read Full Story →