Critical Progress LoadMaster flaw added to CISA's actively-exploited list
CISA added a critical command-injection flaw in Progress LoadMaster, CVE-2026-8037 with a CVSS score of 9.6, to its Known Exploited Vulnerabilities catalog this week. Security firm eSentire says exploitation attempts began June 29, according to The Hacker News and CISA.
CISA has added CVE-2026-8037, a critical pre-authentication command-injection vulnerability in Progress Kemp LoadMaster with a CVSS score of 9.6, to its Known Exploited Vulnerabilities catalog this week, requiring federal agencies to patch it. The flaw allows an unauthenticated attacker to execute arbitrary commands on the load balancer appliance. Security firm eSentire's Threat Response Unit identified exploitation attempts beginning June 29, originating from three tracked IP addresses. It is the second critical LoadMaster flaw to face active exploitation, after CVE-2024-1212 (CVSS 10.0). A public proof-of-concept exploit is now circulating, which researchers expect to drive further attacks. Source: The Hacker News, CISA.