CISA KEV Alert 8/7/2026, 7:02:40 PM

CISA Adds Critical LoadMaster Command Injection Flaw to KEV List

Developing story malware 6 articles tracked
Progress Kemp LoadMaster command injection vulnerability (CVE-2026-8037) exploited in the wild
CyberSIXT Evidence Panel Source marked as original reporting
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Available

CISA has added CVE‑2026‑8037 to its Known Exploited Vulnerabilities catalogue. The entry concerns Progress LoadMaster, specifically the “Progress LoadMaster Command Injection Vulnerability” affecting the LoadMaster appliance. The flaw permits an unauthenticated attacker to execute arbitrary commands on the device by sending unsanitised input to multiple command endpoints.

The vulnerability is a command injection issue that can lead to full remote code execution with the privileges of the LoadMaster service. Attackers can exploit it over the network without needing any credentials. The Common Vulnerability Scoring System rates it at 9.6, classified as CRITICAL, and a patch has been released by the vendor.

Because the CVE is listed in the KEV catalogue, active exploitation has been confirmed in the wild. No known ransomware campaigns have been linked to this flaw at present. CISA has set a remediation deadline of 10 August 2026 for federal agencies to address the issue.

CISA’s required action is: “Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26‑04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26‑04 guidance for cloud services or discontinue use of the product if mitigations are unavailable.

Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26‑04 patching guidelines.” This directive binds Federal Civilian Executive Bureau agencies; all other organisations should review their exposure and apply the available patch or follow the vendor’s mitigation guidance.

For full technical details, refer to the NVD entry at https://nvd.nist.gov/vuln/detail/CVE-2026-8037 and the CISA KEV catalogue.

View CISA KEV Entry

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline