THE U.S. cybersecurity agency CISA has issued a warning urging federal agencies to quickly patch a critical vulnerability (CVE-2026-8037) in Progress Kemp LoadMaster software that has been exploited. This vulnerability, with a CVSS score of 9.6, allows for remote code execution through an OS command injection without requiring authentication. The flaw could be exploited via unsanitized API inputs that let attackers execute arbitrary commands.
Initial exploitation attempts began on June 29, following the release of technical analysis and proof-of-concept code. CISA added the CVE to its Known Exploited Vulnerabilities catalog, giving agencies a limited timeframe to implement fixes.