CISA Warns of Active Exploitation in Progress Kemp LoadMaster Vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (**CISA**) has added a critical command injection flaw in **Progress Kemp LoadMaster** to its Known Exploited Vulnerabilities (KEV) catalog. Tracked as **CVE-2026-8037**, this vulnerability allows unauthenticated attackers to execute arbitrary code, prompting urgent patching recommendations for federal agencies and private organizations alike.

**CISA** recently issued a critical alert, adding a **Progress Kemp LoadMaster** security flaw to its KEV catalog due to confirmed active exploitation.
### Critical Command Injection Flaw Identified
The vulnerability, identified as **CVE-2026-8037** with a CVSS score of 9.6, is a severe command injection flaw. It enables an unauthenticated attacker to execute arbitrary commands on susceptible devices.
**CISA** detailed the issue, stating, "**Progress LoadMaster** contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints."
### Technical Details and Exploitation
In June 2026, **watchTowr Labs** published an analysis highlighting that the flaw resides in the `escape_quotes()` function within the load balancer application. The vulnerability stems from improper handling of user-supplied input, ultimately leading to command injection without requiring valid credentials.
### Active Exploitation Confirmed
This addition to the KEV catalog follows a report from **eSentire** a little over a month prior, which noted active, albeit largely unsuccessful, exploitation attempts targeting the flaw.

**eSentire** identified the following IP addresses as sources of these attacks:
* 192.42.116[.]58
* 192.42.116[.]105
* 146.70.139[.]154
Telemetry data from **KEVIntel** indicates a broader scope of activity, logging 792 exploitation attempts over the past 41 days. These attempts originated from 65 unique IP addresses across 18 countries, including Australia, China, Indonesia, Japan, Poland, and the U.S. The most recent activity was recorded on August 4, 2026, with five detected exploitation attempts.
### Urgent Patching Recommended
Given the confirmed active exploitation, **CISA** strongly recommends that Federal Civilian Executive Branch (**FCEB**) agencies apply the necessary patches by August 10, 2026. This directive is in accordance with Binding Operational Directive (**BOD**) 26-04, emphasizing the urgency for all organizations utilizing **Progress Kemp LoadMaster** to secure their networks promptly.