The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed active exploitation of a critical command injection vulnerability in Progress Kemp LoadMaster, a widely used Application Delivery Controller (ADC) and load balancer deployed by organizations including major cloud providers and government entities.
The flaw, tracked as CVE-2026-8037 and carrying a CVSS score of 9.6, allows unauthenticated attackers to execute arbitrary commands on unpatched LoadMaster appliances by abusing unsanitized inputs across multiple API command endpoints. Because the vulnerability requires no authentication, it presents a straightforward path to full appliance compromise for any exposed instance.
Widespread deployment footprint
Kemp LoadMaster is used to distribute web traffic, optimize application performance, and maintain service availability. Progress Software states that 80% of Fortune 500 companies use its products, with more than 100,000 LoadMaster deployments worldwide, including customers such as Amazon and the U.S. Air Force.
Internet scanning service Shadowserver has identified nearly 300 Kemp LoadMaster instances currently exposed online, though it is unclear how many are honeypots or have already been patched. According to The Hacker News, researchers have logged 792 reported exploit attempts against the vulnerability.
Patches available since June
Progress released fixes for CVE-2026-8037 in June, addressing versions GA v7.2.63.1 and LTSF v7.2.54.17 or older. The company also confirmed that all MOVEit WAF versions prior to GA v7.2.63.2 are affected. Organizations running older builds remain at risk until updated.
Federal deadline and broader guidance
CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on Friday, triggering Binding Operational Directive 26-04, which requires Federal Civilian Executive Branch agencies to remediate their systems within three days. CISA noted that command injection flaws of this type are a frequent attack vector against federal networks and pose significant enterprise risk. While the directive is mandatory only for federal agencies, CISA urged all organizations running LoadMaster to prioritize patching immediately.
This disclosure follows a separate incident last month in which Progress warned ShareFile customers using Storage Zone Controllers of a “credible external security threat,” later linked to a high-severity path traversal zero-day. Progress said it found no evidence of unauthorized access tied to that issue. Security teams managing Progress product deployments should treat both incidents as a signal to review patch status across their full Progress software stack.
