All incidents

Progress LoadMaster command injection flaw (CVE-2026-8037) exploited in the wild

campaignopenJun 9, 2026 — Aug 10, 2026
Progress LoadMaster command injection flaw (CVE-2026-8037) exploited in the wild

CISA has added a critical command injection flaw in Progress Kemp LoadMaster to its Known Exploited Vulnerabilities catalogue after confirming active exploitation in the wild. The vulnerability, tracked as CVE-2026-8037, carries a CVSS score of 9.6 and allows unauthenticated attackers to execute arbitrary code on affected appliances. Federal civilian agencies have been ordered to apply the vendor patch by 10 August 2026.

The flaw resides in several LoadMaster API endpoints where user‑supplied input is not properly sanitised before being passed to the underlying operating system shell. By crafting a malicious request an attacker can inject OS commands and gain full control of the device with the privileges of the LoadMaster service. Progress has released a security update that addresses the issue in all supported versions, details of which are available in the June 2026 security bulletin.

Exploitation attempts were first observed on 29 June 2026, shortly after proof‑of‑concept code appeared online. Although no confirmed post‑compromise activity has been reported, the addition to the KEV catalog signals that the vulnerability is being used in attacks. CISA also recently highlighted a separate critical flaw in Microsoft SharePoint Server (CVE-2026-45659) that is likewise under active exploitation, as noted in a SecurityWeek report.

Defenders should immediately install the LoadMaster patch from Progress and verify that the update applies to all appliances in their inventory. Organisations are advised to review API access rules, block any unnecessary interfaces at the network perimeter, and enable detailed logging of command execution attempts.

Where immediate patching is not feasible, administrators can consider disabling the affected API functions or deploying a web application firewall rule that filters out suspicious payloads. Monitoring for unexpected shell spawning or privileged process creation remains a key detection strategy until the fix is fully deployed.

The same bulletin that disclosed CVE-2026-8037 also noted a medium severity issue (CVE-2026-33691) involving improper input validation in the LoadMaster administrative interface. While less severe, chaining such flaws with the command injection could increase the impact of an attack chain. Administrators should therefore assess both vulnerabilities when prioritising remediation, with further information available in the Progress advisory.

Keeping an eye on CISA’s Known Exploited Vulnerabilities feed helps security teams focus on flaws that are already being used in the wild. Subscribing to the catalogue in CSV or JSON format and integrating it with vulnerability scanners can accelerate patch cycles. Regular configuration reviews and penetration testing of exposed management interfaces further reduce the likelihood of successful exploitation.

Intelligence briefing updated Aug 10, 2026

CVE-2026-10134 10.0 CVE-2026-48282 10.0 KEV CVE-2026-48558 10.0 KEV CVE-2026-8037 9.6 KEV CVE-2026-50751 9.3 KEV CVE-2026-45659 8.8 KEV CVE-2026-33691 6.8
Root sourcecommunity.progress.com
Timeline Coverage

Swipe to explore timeline