← All stories
● Covered by 1 source · 1 reportHigh impact1 negative

CISA Warns of Active Exploitation of Critical Progress Kemp LoadMaster Vulnerability

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • CISA warns of active exploitation of CVE-2026-8037 in Kemp LoadMaster.
  • Vulnerability allows unauthenticated command injection on affected devices.
  • Progress Software released patches in June for LoadMaster and MOVEit WAF.
  • CISA ordered federal agencies to patch within three days.

Active Exploitation of Critical Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has reported that a critical-severity command injection vulnerability in Progress Kemp LoadMaster, tracked as CVE-2026-8037, is currently being exploited by malicious actors. This flaw enables unauthenticated attackers to execute arbitrary commands on unpatched LoadMaster appliances by exploiting unsanitized API inputs.

Widespread Impact and Usage

Kemp LoadMaster is an Application Delivery Controller (ADC) and server load balancer used globally by various organizations, including major tech companies and government entities like Amazon and the U.S. Air Force. Progress Software, the developer, states that 80% of Fortune 500 companies use its products, with over 100,000 LoadMaster deployments worldwide. The vulnerability also affects all MOVEit WAF versions prior to GA v7.2.63.2.

Patch Availability and CISA Directive

Progress Software released security updates in June to address the vulnerability in Kemp LoadMaster (GA v7.2.63.1 or older and LTSF v7.2.54.17 or older). CISA has added this flaw to its catalog of actively exploited vulnerabilities and has mandated that U.S. Federal Civilian Executive Branch (FCEB) agencies secure their servers within three days, as per Binding Operational Directive 26-04. CISA urges all organizations to prioritize patching CVE-2026-8037 to prevent attacks.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning that a critical command injection vulnerability (CVE-2026-8037) in Progress Kemp LoadMaster is being actively exploited by attackers. This flaw allows unauthenticated attackers to execute arbitrary commands on affected LoadMaster appliances, which are widely used by tech companies and government entities for traffic distribution and application performance.