CISA Warns of Active Exploitation in Progress Kemp LoadMaster Vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (**CISA**) has issued a stark warning regarding active exploitation of a critical command injection vulnerability in **Progress Kemp LoadMaster** products. Tracked as **CVE-2026-8037**, this flaw allows unauthenticated attackers to execute arbitrary commands, posing a significant risk to the numerous organizations, including Fortune 500 companies and government entities, that rely on these Application Delivery Controllers (ADCs).

**CISA** has added **CVE-2026-8037** to its catalog of actively exploited vulnerabilities, mandating that U.S. Federal Civilian Executive Branch (**FCEB**) agencies patch their systems within three days. This directive, stemming from Binding Operational Directive 26-04, underscores the severity and immediate threat posed by this flaw.
### The Vulnerability: CVE-2026-8037
**Kemp LoadMaster** is a widely used Application Delivery Controller (ADC) and server load balancer, crucial for optimizing application performance and ensuring high service availability across numerous tech companies and government entities, including **Amazon** and the **U.S. Air Force**. **Progress Software** states that its products are utilized by 80% of Fortune 500 companies, with **Kemp LoadMaster** alone boasting over 100,000 deployments globally.
The critical command injection vulnerability, **CVE-2026-8037**, enables unauthenticated attackers to execute arbitrary commands on unpatched **LoadMaster** appliances. This is achieved by exploiting unsanitized API inputs across multiple command endpoints.
### Patching and Impact
**Progress Software** released security updates in June to address this vulnerability. The flaw impacts **Kemp LoadMaster** versions GA v7.2.63.1 or older and LTSF v7.2.54.17 or older. Additionally, it affects all **MOVEit WAF (Web Application Firewall)** versions prior to GA v7.2.63.2.
According to the Internet threat watchdog **Shadowserver**, approximately 300 **Kemp LoadMaster** instances are currently exposed online. However, it remains unclear how many of these have been secured or if some are honeypots.
### Broader Implications and Recent Incidents
While the **CISA** directive specifically targets U.S. government agencies, the agency strongly advises all organizations to prioritize patching **CVE-2026-8037** to mitigate potential attacks. **CISA** emphasized that such vulnerabilities are frequent attack vectors for malicious actors and present significant risks to any enterprise.
This incident follows another recent security alert from **Progress Software**. Last month, the company urged **ShareFile** customers using Storage Zone Controllers to shut down their servers due to a βcredible external security threat.β Days later, patches were released for a high-severity **ShareFile** path traversal zero-day vulnerability, although the company stated there was no indication of unauthorized access to customer accounts or data at that time.