CVE Tools
Back to feed
Exploited in the wild Progress Kemp LoadMaster rce MOVEit WAF Progress Software network-edge

Critical Progress LoadMaster flaw now actively exploited in attacks

BleepingComputer·By Sergiu Gatlan··2 min read
CVE Tools coverage

CISA has warned that threat actors are actively leveraging a critical command injection vulnerability in Progress Kemp LoadMaster devices. Tracked as CVE-2026-8037, this flaw permits unauthenticated users to execute arbitrary commands by manipulating unsanitized API inputs on specific endpoints.

The issue affects Kemp LoadMaster installations running GA v7.2.63.1 or older, along with LTSF v7.2.54.17 or older, and also impacts all MOVEit WAF versions before GA v7.2.63.2. Progress Software released fixes in June, and recent analysis by Shadowserver indicates that nearly 300 instances remain exposed online. CISA has added the CVE to its Known Exploited Vulnerabilities catalog, requiring US federal agencies to remediate the risk within three days under Binding Operational Directive 26-04.