Critical Progress LoadMaster CVE Enables Unauthenticated Command Injection
CISA has added CVE-2026-8037, a critical command injection vulnerability in Progress Kemp LoadMaster, to its Known Exploited Vulnerabilities Catalog. Attackers are actively exploiting this flaw to execute arbitrary commands on unpatched appliances. Over 100,000 LoadMaster deployments worldwide are at risk, including systems used by Fortune 500 companies and U.S. government agencies.
What Happened: Critical Progress LoadMaster Flaw Now Under Active Attack
On August 7, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are actively exploiting a critical command injection vulnerability in Progress Kemp LoadMaster. Tracked as CVE-2026-8037, this flaw enables unauthenticated attackers to execute arbitrary commands on vulnerable appliances by exploiting unsanitized API inputs across multiple command endpoints.
Progress Software released security updates in June 2026 to patch the vulnerability. However, evidence of active exploitation has now emerged, prompting CISA to add the flaw to its Known Exploited Vulnerabilities (KEV) Catalog. Federal Civilian Executive Branch (FCEB) agencies must patch their systems within three days under Binding Operational Directive 26-04.
Moreover, the vulnerability also impacts all MOVEit WAF versions before GA v7.2.63.2. Progress Software confirmed both products share the same vulnerable code path. Consequently, organizations running either LoadMaster or MOVEit WAF must assess their exposure immediately.
Technical Details of the CVE-2026-8037 Vulnerability
CVE-2026-8037 is a command injection vulnerability in Progress Kemp LoadMaster. Attackers can exploit unsanitized API inputs in multiple command endpoints to inject and execute arbitrary system commands without authentication.
The following products and versions are affected:
- Kemp LoadMaster GA v7.2.63.1 or older
- Kemp LoadMaster LTSF v7.2.54.17 or older
- MOVEit WAF all versions before GA v7.2.63.2
Internet threat watchdog Shadowserver currently tracks nearly 300 Kemp LoadMaster instances exposed online. While some may be honeypots or already patched, the exposure window remains significant. In addition, the vulnerability’s unauthenticated nature makes it trivial to exploit at scale.
Business and Operational Impact
The impact of CVE-2026-8037 extends far beyond a single product line. Progress Software states that 80% of Fortune 500 companies use its products and services. Kemp LoadMaster alone has over 100,000 deployments worldwide. Furthermore, government entities such as the U.S. Air Force rely on LoadMaster for traffic distribution and application availability.
Key impact areas include:
- Complete appliance compromise: Unauthenticated command execution grants total control of affected LoadMaster appliances
- Lateral movement: Compromised load balancers sit at the network edge, making them ideal pivot points into internal infrastructure
- Service disruption: Attackers can reconfigure traffic rules, redirect users to malicious endpoints, or drop legitimate traffic
- Data exposure: Load balancers often terminate TLS; compromised appliances may expose decrypted traffic
- Compliance violations: Federal agencies face BOD 26-04 remediation deadlines; failure to patch risks audit findings
Mitigation and Recommendations
Defenders should treat CVE-2026-8037 as a high-priority patching target. CISA’s KEV Catalog addition signals confirmed, ongoing exploitation in the wild.
Immediate Actions for Defenders
- Upgrade immediately: Apply Progress Software’s June 2026 security updates to LoadMaster GA v7.2.63.1+ or LTSF v7.2.54.17+
- Patch MOVEit WAF: Upgrade to MOVEit WAF GA v7.2.63.2 or newer
- Audit exposure: Identify all internet-facing LoadMaster and MOVEit WAF instances via Shadowserver data or internal asset inventories
- Check for compromise: Review appliance logs for anomalous API calls, unauthorized configuration changes, or unexpected admin sessions
- Restrict management access: Limit administrative interfaces to trusted IP ranges until patching is complete
Detection and Monitoring Guidance
Security teams should monitor LoadMaster API access logs for unusual command strings, unexpected endpoint access, or traffic spikes to management interfaces. In addition, network detection rules should flag suspicious outbound connections from load balancer subnets. Finally, ensure SIEM and EDR coverage extends to appliance operating systems where possible.
Bottom line: CVE-2026-8037 is a critical, unauthenticated command injection flaw actively exploited against widely deployed enterprise infrastructure. Patch now, verify exposure, and check for signs of compromise.
Incident Summary
| CVE ID / Incident: | CVE-2026-8037 |
| Affected Systems: | Progress Kemp LoadMaster (GA ≤ v7.2.63.1, LTSF ≤ v7.2.54.17); MOVEit WAF (< v7.2.63.2) |
| Disclosure Date: | June 2026 (patched); August 7, 2026 (CISA KEV addition) |
| Patch Status: | Available — patches released June 2026 |
| Severity: | Critical — unauthenticated command injection |
| Exploitation Status: | Actively exploited in the wild (CISA KEV confirmed) |
References
- BleepingComputer, “Critical Progress LoadMaster flaw now actively exploited in attacks,” August 10, 2026, https://www.bleepingcomputer.com/news/security/cisa-warns-of-critical-progress-loadmaster-flaw-exploited-in-attacks/, accessed August 11, 2026.
- CISA, “CISA Adds One Known Exploited Vulnerability to Catalog,” August 7, 2026, https://www.cisa.gov/news-events/alerts/2026/08/07/cisa-adds-one-known-exploited-vulnerability-catalog, accessed August 11, 2026.
- Progress Software, “LoadMaster Critical Security Bulletin — June 2026 (CVE-2026-8037, CVE-2026-33691),” June 2026, https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691, accessed August 11, 2026.
- Shadowserver, “Kemp LoadMaster Internet Exposure Statistics,” 2026, https://dashboard.shadowserver.org/statistics/iot-devices/time-series/, accessed August 11, 2026.