THE U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a Progress LoadMaster vulnerability, identified as CVE-2026-8037 with a CVSS score of 9.6, to its Known Exploited Vulnerabilities catalog. This vulnerability allows unauthenticated attackers to execute arbitrary commands through OS Command Injection on multiple API endpoints of Progress ADC Products. Active exploitation attempts were observed starting June 29, 2026, although no successful post-compromise activity was detected. Organizations are urged to apply relevant security patches, and federal agencies must address this vulnerability by August 10, 2026.
CISA flags exploited LoadMaster bug CVE-2026-8037, urges patch
CyberSIXT Evidence Panel
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
CISA flags exploited LoadMaster bug CVE-2026-8037, urges patch
securityaffairs.com
-
CISA Flags Progress LoadMaster Injection Flaw CVE-2026-8037
cybersixt.com
-
CISA Adds Critical LoadMaster Command Injection Flaw to KEV List
cybersixt.com
-
Weekly Threat Intelligence: The July 2026 Breaches
cybersixt.com
-
CVE-2026-8037: Progress Kemp LoadMaster RCE Exploited in the Wild
cybersixt.com
-
Kemp LoadMaster zero day RCE exploited PoC surfaces patch urged
cybersixt.com
-
LoadMaster flaw lets attackers run root commands remotely
cybersixt.com
-
Check Point VPN, Kemp LoadMaster hit by CVE-2026-50751 exploit
cybersixt.com