Exploited in the wild Progress Kemp LoadMaster rce MOVEit WAF Progress Software network-edge
CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability
CVE Tools coverage
CISA has added CVE-2026-8037 to its Known Exploited Vulnerabilities catalog after confirming active in-the-wild attacks against Progress Kemp LoadMaster appliances. This critical vulnerability (CVSS 9.6) allows unauthenticated attackers to achieve remote code execution by injecting commands through unsanitized API inputs.
The flaw stems from improper memory initialization in versions prior to 7.2.63.1 for GA and 7.2.54.17 for LTSF releases, affecting other products including MOVEit WAF. Administrators are advised to apply patches immediately to prevent potential compromise of network edge devices.