Attackers are actively exploiting a critical flaw in Progress Kemp LoadMaster, a widely used load balancer and application delivery product, and organizations running it need to patch quickly. The bug, CVE-2026-8037, is an unauthenticated command-injection vulnerability in multiple API endpoints that can let outsiders run arbitrary commands on vulnerable appliances. It affects LoadMaster GA v7.2.63.1 or older, LTSF v7.2.54.17 or older, and MOVEit WAF versions before GA v7.2.63.2; CISA added it to the Known Exploited Vulnerabilities catalog and gave U.S. federal agencies three days to remediate.
Why it matters: This can let remote attackers take over exposed traffic-management appliances that sit in front of important business and government services. Organizations using affected LoadMaster or MOVEit WAF versions should patch immediately and review internet-exposed instances for compromise.
Sergiu Gatlan
2026.08.10
100% relevant
This article establishes a new tracked story by adding the key news hook that CVE-2026-8037 is being actively exploited and has been added to CISA's KEV catalog, making it more than a routine patch advisory.
Ionut Arghire
2026.08.10
99% relevant
This article is a direct update on the same event, adding that CISA has placed CVE-2026-8037 in the KEV catalog, given federal agencies three days to patch, and reiterating exploitation timing and technical details from Progress, ZDI, watchTowr, and eSentire.
← Back to all stories