Critical Kemp LoadMaster flaw actively exploited, CISA orders emergency patch
CISA confirmed active exploitation of CVE-2026-8037, a 9.6-severity command injection flaw in Progress Kemp LoadMaster load balancers, adding it to its known-exploited list on August 7. Trackers logged 792 exploitation attempts from 65 IP addresses across 18 countries in 41 days,
CISA confirmed active exploitation of CVE-2026-8037, a command injection flaw in Progress Kemp LoadMaster load balancers rated 9.6 out of 10 in severity, adding it to its known-exploited-vulnerabilities catalog on August 7. Researchers at watchTowr Labs traced the bug to a flawed input-sanitization function that lets unauthenticated attackers run arbitrary commands. Tracking firm KEVIntel logged 792 exploitation attempts from 65 IP addresses across 18 countries over 41 days, and monitoring group Shadowserver still counts nearly 300 exposed instances online. Progress Software released a fix in June, and federal civilian agencies were ordered to patch by August 10 under a binding CISA directive.