THE U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a Progress LoadMaster vulnerability, identified as CVE-2026-8037 with a CVSS score of 9.6, to its Known Exploited Vulnerabilities catalog. This vulnerability allows unauthenticated attackers to execute arbitrary commands through OS Command Injection on multiple API endpoints of Progress ADC Products. Active exploitation attempts were observed starting June 29, 2026, although no successful post-compromise activity was detected. Organizations are urged to apply relevant security patches, and federal agencies must address this vulnerability by August 10, 2026.
CISA flags exploited LoadMaster bug CVE-2026-8037, urges patch
CyberSIXT Evidence Panel
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
CISA urges patch Progress Kemp LoadMaster CVE-2026-8037 RCE flaw
securityweek.com
-
CISA flags exploited LoadMaster bug CVE-2026-8037, urges patch
securityaffairs.com
-
Metabase SQL Injection Zero-Day (CVSS 10) Exploited
securityonline.info
-
CISA Flags Progress LoadMaster Injection Flaw CVE-2026-8037
cisa.gov
-
CISA Adds Critical LoadMaster Command Injection Flaw to KEV List
cisa.gov