CISA Warns of Critical Progress LoadMaster Flaw Actively Exploited by Hackers

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are actively exploiting a critical-severity command injection vulnerability in Progress Kemp LoadMaster. The flaw, tracked as CVE-2026-8037, allows unauthenticated attackers to execute arbitrary commands on unpatched appliances by exploiting unsanitized API inputs across multiple command endpoints. Nearly 300 Kemp LoadMaster instances are currently exposed online, according to threat monitoring organization Shadowserver.

Kemp LoadMaster is a widely used application delivery controller and server load balancer trusted by major tech companies and government entities, including Amazon and the U.S. Air Force. Progress Software reports that 80% of Fortune 500 companies use its products, with over 100,000 LoadMaster deployments worldwide. The vulnerability affects all versions before GA v7.2.63.1 and LTSF v7.2.54.17, as well as all MOVEit Web Application Firewall versions prior to GA v7.2.63.2.

CISA adds the flaw to its catalog of actively exploited vulnerabilities and orders federal agencies to secure their servers within three days. While this directive applies specifically to U.S. government agencies, CISA urges all organizations to prioritize patching immediately. Progress Software released security updates in June to address the vulnerability, and defenders are encouraged to apply these patches without delay to prevent potential compromise.

Read More at the original source →