The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has reported that a critical-severity command injection vulnerability in Progress Kemp LoadMaster, tracked as CVE-2026-8037, is currently being exploited by malicious actors. This flaw enables unauthenticated attackers to execute arbitrary commands on unpatched LoadMaster appliances by exploiting unsanitized API inputs.
Kemp LoadMaster is an Application Delivery Controller (ADC) and server load balancer used globally by various organizations, including major tech companies and government entities like Amazon and the U.S. Air Force. Progress Software, the developer, states that 80% of Fortune 500 companies use its products, with over 100,000 LoadMaster deployments worldwide. The vulnerability also affects all MOVEit WAF versions prior to GA v7.2.63.2.
Progress Software released security updates in June to address the vulnerability in Kemp LoadMaster (GA v7.2.63.1 or older and LTSF v7.2.54.17 or older). CISA has added this flaw to its catalog of actively exploited vulnerabilities and has mandated that U.S. Federal Civilian Executive Branch (FCEB) agencies secure their servers within three days, as per Binding Operational Directive 26-04. CISA urges all organizations to prioritize patching CVE-2026-8037 to prevent attacks.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning that a critical command injection vulnerability (CVE-2026-8037) in Progress Kemp LoadMaster is being actively exploited by attackers. This flaw allows unauthenticated attackers to execute arbitrary commands on affected LoadMaster appliances, which are widely used by tech companies and government entities for traffic distribution and application performance.