Critical Progress LoadMaster flaw now actively exploited in attacks
CISA has warned that threat actors are actively leveraging a critical command injection vulnerability in Progress Kemp LoadMaster devices. Tracked as CVE-2026-8037, this flaw permits unauthenticated users to execute arbitrary commands by manipulating unsanitized API inputs on specific endpoints.
The issue affects Kemp LoadMaster installations running GA v7.2.63.1 or older, along with LTSF v7.2.54.17 or older, and also impacts all MOVEit WAF versions before GA v7.2.63.2. Progress Software released fixes in June, and recent analysis by Shadowserver indicates that nearly 300 instances remain exposed online. CISA has added the CVE to its Known Exploited Vulnerabilities catalog, requiring US federal agencies to remediate the risk within three days under Binding Operational Directive 26-04.