ZeroHour
Security Affairspublished ()ingested @securityaffairs

U.S. CISA adds a Progress LoadMaster flaw to its Known Exploited Vulnerabilities catalog

criticalExploit / PoC exploited in the wildimportance 60CVE-2026-8037

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-8037
Unauthenticated OS Command Injection RCE in Progress Kemp LoadMaster

Progress Kemp LoadMaster, the application delivery controller/load balancer sold by Progress Software (formerly Kemp), contains an unauthenticated OS command injection flaw (CWE-77) in its API: unsanitized input sent to multiple command endpoints allows arbitrary operating-system commands to be executed on the appliance. Because the affected endpoints require no authentication, any remote attacker with network access to the appliance's API or management interface can trigger the bug directly; public research by WatchTowr describes it as a pre-authentication RCE chain (involving uninitialized memory/quote handling) that can yield root-level command execution. Successful exploitation gives an attacker full control of the appliance, consistent with the Critical 9.8 CVSS 3.1 score (network-exploitable, no privileges or user interaction, high impact on confidentiality, integrity and availability). Organizations running Progress Kemp LoadMaster appliances are affected, especially those where the management or API interface is reachable from the internet. Exploitation is confirmed and ongoing: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-08-07 after 792 reported exploit attempts, and EPSS assigns a 99.6% probability of exploitation within 30 days.

Do: Upgrade LoadMaster to the fixed release identified in Progress's security advisory (fixed version numbers are not specified in this data). Until patched, restrict the LoadMaster API/management interface to trusted networks or VPN access, and review appliance logs for signs of unexpected command execution given confirmed in-the-wild exploitation. Because the flaw is on CISA's KEV catalog, US federal agencies must apply mitigations per BOD 26-04 by the required deadline — or discontinue use of the product if mitigations are unavailable — and evaluate each asset's internet exposure.

9.8100% KEV PoC
  • Progress LoadMaster (Kemp LoadMaster ADC/load balancer)
  • Progress Connection Manager for ObjectScale
  • Progress ECS Connection Manager
  • +1 more
largetens of thousands of internet-exposed LoadMaster appliances (order of magnitude: 10,000–100,000 devices)
Full article266 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Progress LoadMaster vulnerability to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Progress LoadMaster vulnerability, tracked as CVE-2026-8037 (CVSS score of 9.6), to its Known Exploited Vulnerabilities (KEV) catalog.

The vulnerability is an OS Command Injection Remote Code Execution issue that resides in API in Progress ADC Products. An unauthenticated attacker can trigger the flaw to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints

In early July, cybersecurity firm eSentire observed exploitation attempts targeting CVE-2026-8037. Activity began June 29, 2026, but the attacks failed and no post-compromise activity was detected. Researchers warned that the public PoC and technical details could lead to increased exploitation.

“Beginning on June 29th, 2026, eSentire’s Threat Response Unit (TRU) identified exploitation attempts targeting the critical Progress Kemp LoadMaster vulnerability CVE-2026-8037. The vulnerability was initially disclosed on June 4th and functional Proof-of-Concept (PoC) exploit code was released on June 29th. CVE-2026-8037 (CVSS: 9.6), is an OS Command Injection Remote Code Execution (RCE) vulnerability which allows an unauthenticated attacker to execute arbitrary commands on the LoadMaster appliance.” eSentire reports.

“As active exploitation attempts have been identified, it is critical that organizations apply the relevant security patches immediately.”

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the vulnerability by the end of this week, on August 10, 2026.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/196863/hacking/u-s-cisa-adds-a-progress-loadmaster-flaw-to-its-known-exploited-vulnerabilities-catalog.html