CISA Lists Exploited Progress Kemp LoadMaster Command Injection Flaw

The U.S. Cybersecurity and Infrastructure Security Agency has added a critical vulnerability in Progress Kemp LoadMaster to its Known Exploited Vulnerabilities catalog after reports of active exploitation. The issue, CVE-2026-8037, has a CVSS score of 9.6 and is a command injection vulnerability that can enable arbitrary code execution on affected appliances.
CISA said an unauthenticated attacker can execute arbitrary commands by exploiting unsanitized input in multiple LoadMaster command endpoints. The flaw affects a product used to provide load-balancing functions, making patching and exposure assessment an immediate operational concern for organizations running susceptible devices.
Exploit activity prompts KEV addition
KEVIntel telemetry recorded 792 exploitation attempts over 41 days, originating from 65 unique IP addresses in 18 countries. The observed locations included Australia, China, Indonesia, Japan, Poland, and the United States. The most recent activity in the dataset occurred on August 4, 2026, when five attempts were detected.
eSentire had reported active exploitation efforts more than a month before the KEV listing, while noting that the attempts it observed were largely unsuccessful. The Canadian security vendor identified 192.42.116[.]58, 192.42.116[.]105, and 146.70.139[.]154 among the IP addresses used in the activity.
Technical cause and patching deadline
watchTowr Labs described the weakness in a June 2026 analysis as an input-handling problem in a function called escape_quotes() within the load balancer application. Improper handling of user-supplied input can result in command injection, allowing an attacker to run commands without valid LoadMaster credentials. The risk follows the pattern outlined in RCE-prone LoadMaster exposure demanding prompt remediation of an RCE-prone LoadMaster exposure demanding prompt verification and remediation.
For Federal Civilian Executive Branch agencies, CISA recommended applying the necessary patches by August 10, 2026, in line with Binding Operational Directive 26-04. Inclusion in KEV signals that the vulnerability has been exploited in the wild and places it within the federal remediation process.
Business implication
Security teams should identify all internet-facing and internal Progress Kemp LoadMaster appliances, confirm their patch status, and prioritize the required remediation. They should also review available appliance and network logs for suspicious command execution or connections associated with the reported exploitation activity, then validate that the patched devices are no longer exposed to the vulnerable condition.

