CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Progress Kemp LoadMaster CVE-2026-8037 Added to CISA KEV After 792 Exploit Attempts

August 8, 2026

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical command injection vulnerability affecting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. Tracked as CVE-2026-8037 with a CVSS score of 9.6, the flaw allows an unauthenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.

According to CISA, the vulnerability stems from improper handling of user-supplied input in the escape_quotes() function within the load balancer application, as detailed in an analysis by watchTowr Labs published in June 2026. Successful exploitation enables remote code execution without requiring valid credentials.

Active exploitation attempts were first reported by eSentire, a Canadian security vendor, which observed attacks originating from IP addresses 192.42.116[.]58, 192.42.116[.]105, and 146.70.139[.]154. Telemetry from KEVIntel recorded 792 exploitation attempts over 41 days, originating from 65 unique IP addresses across 18 countries, including Australia, China, Indonesia, Japan, Poland, and the United States. The most recent activity was detected on August 4, 2026, with five attempts.

In response, CISA has mandated that Federal Civilian Executive Branch (FCEB) agencies apply the necessary patches by August 10, 2026, in accordance with Binding Operational Directive (BOD) 26-04. Organizations using Progress Kemp LoadMaster are strongly urged to prioritize patching and review their security posture to mitigate potential exploitation.

CVEs: CVE-2026-8037, CVE-2026-50522

Companies: Progress, watchTowr Labs, eSentire, KEVIntel

Products: Progress Kemp LoadMaster