www.securityweek.com 8/10/2026, 9:41:11 AM · external

CISA urges patch Progress Kemp LoadMaster CVE-2026-8037 RCE flaw

CISA urges patch Progress Kemp LoadMaster CVE-2026-8037 RCE flaw
Developing story campaign 9 articles tracked
Progress LoadMaster command injection flaw (CVE-2026-8037) exploited in the wild
CyberSIXT Evidence Panel
CISA KEV Listed in KEV
Patch Patch Available

THE U.S. cybersecurity agency CISA has issued a warning urging federal agencies to quickly patch a critical vulnerability (CVE-2026-8037) in Progress Kemp LoadMaster software that has been exploited. This vulnerability, with a CVSS score of 9.6, allows for remote code execution through an OS command injection without requiring authentication. The flaw could be exploited via unsanitized API inputs that let attackers execute arbitrary commands.

Initial exploitation attempts began on June 29, following the release of technical analysis and proof-of-concept code. CISA added the CVE to its Known Exploited Vulnerabilities catalog, giving agencies a limited timeframe to implement fixes.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline