Actively Exploited Flaw in Progress LoadMaster Added to CISA's Must-Patch List
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog after confirming it is being actively exploited by attackers. The flaw, CVE-2026-8037, is a command injection vulnerability in Progress LoadMaster, a widely used load-balancing product. Command injection vulnerabilities like this one are a common and dangerous attack method, as they can allow attackers to run unauthorised commands on affected systems.
While CISA's related directive, BOD 26-04, formally applies only to U.S. federal agencies, the agency encourages all organisations, including small and medium businesses, to adopt the same risk-based approach: prioritise patching vulnerabilities that are known to be exploited in the wild, especially on systems exposed to the internet. Vulnerabilities added to the KEV Catalog are considered high-risk because there is confirmed evidence of real-world attacks, not just theoretical exposure.
Australian businesses using Progress LoadMaster or similar network infrastructure products should check with their IT provider or vendor to confirm whether they are running an affected version and apply available patches as soon as possible. Delaying action on known exploited vulnerabilities significantly increases the risk of compromise.