CVE Tools
Back to feed
Exploited in the wild Progress Kemp LoadMaster rce MOVEit WAF Progress Software network-edge

CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability

SecurityWeek·By Ionut Arghire··2 min read
CVE Tools coverage

CISA has added CVE-2026-8037 to its Known Exploited Vulnerabilities catalog after confirming active in-the-wild attacks against Progress Kemp LoadMaster appliances. This critical vulnerability (CVSS 9.6) allows unauthenticated attackers to achieve remote code execution by injecting commands through unsanitized API inputs.

The flaw stems from improper memory initialization in versions prior to 7.2.63.1 for GA and 7.2.54.17 for LTSF releases, affecting other products including MOVEit WAF. Administrators are advised to apply patches immediately to prevent potential compromise of network edge devices.