A critical security flaw in Progress Kemp LoadMaster is an actively exploited vulnerability after the U.S. Cybersecurity and Infrastructure Security Agency added it to the Known Exploited Vulnerabilities catalog. The flaw is tracked as CVE-2026-8037 and carries a CVSS score of 9.6. It is an OS command injection vulnerability that can allow an unauthenticated attacker to execute arbitrary commands on a vulnerable LoadMaster appliance. CISA’s action confirms that the issue has moved beyond a theoretical security risk.

CVE-2026-8037-command-injection-exploit

The vulnerability affects the API of Progress ADC products and is caused by improper handling of user-controlled input. Security researchers found that the problem is connected to the escape_quotes() function. The vulnerable code does not properly terminate data stored in a heap buffer, which can result in out-of-bounds memory reads. Attackers can abuse this behavior to place command injection content into memory and ultimately cause the appliance to execute commands through the system() function.

One important part of the problem is that attackers do not need valid credentials to attempt exploitation. The vulnerability can be reached through the /accessv2 endpoint when the LoadMaster API is enabled. If successfully exploited, an attacker could execute arbitrary commands on the underlying appliance with serious consequences. LoadMaster devices are commonly placed at the network edge and can have access to important internal services, meaning a compromised appliance could potentially become a starting point for further activity inside an organization.

CVE-2026-8037-global-cyber-attack-map

The flaw was publicly disclosed on June 4, 2026, and a functional proof-of-concept exploit was released on June 29. Shortly after that release, eSentire’s Threat Response Unit began identifying exploitation attempts against CVE-2026-8037. eSentire reported that the attempts it observed were unsuccessful, and no post-compromise activity was detected in those cases. However, the security company warned that exploitation attempts could increase because working exploit code was publicly available.

Additional telemetry shows that attackers have continued testing the vulnerability at scale. According to data reported by KEVIntel, 792 exploitation attempts were observed over a 41-day period from 65 unique IP addresses across 18 countries. Activity included Australia, China, Indonesia, Japan, Poland and the United States. Five exploitation attempts were recorded as recently as August 4, showing that scanning and attack activity has continued after the vulnerability became public.

LoadMaster-command-injection-cyber-attack

CISA’s decision to place CVE-2026-8037 in its KEV catalog gives the issue a higher priority for organizations responsible for infrastructure. Federal Civilian Executive Branch agencies have been directed to apply the required security updates by August 10, 2026, under Binding Operational Directive 26-04. While the deadline specifically applies to U.S. federal agencies, the confirmed exploitation is an important warning for other organizations using LoadMaster appliances, especially those that expose management or API services to untrusted networks.

Progress has released fixed versions for the affected LoadMaster branches. For LoadMaster GA, versions 7.2.63.1 and earlier are affected, with version 7.2.63.2 listed as the resolved release. For LoadMaster LTSF, versions 7.2.54.17 and earlier are affected, with version 7.2.54.18 providing the fix. Organizations should identify deployed versions, apply the appropriate update after reviewing business impact, and pay particular attention to systems where the API is enabled or management interfaces are reachable from outside trusted networks.

LoadMaster-CVE-2026-8037-security-vulnerability

The current situation highlights why internet-facing network appliances need the same urgent patching attention as servers. CVE-2026-8037 combines a high severity rating, unauthenticated command execution and public exploit information, while real exploitation attempts have already been observed. Although the attacks reported by eSentire did not succeed, that does not remove the risk as attackers continue to study and test the flaw. Organizations running Progress Kemp LoadMaster should therefore prioritize the available fixes and review their systems for signs of attempted exploitation.

Stay alert, and keep your security measures updated!

Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news