Government Advisory

Actively Exploited Flaw in Progress LoadMaster Added to CISA's Must-Patch List

CISA · 7 Aug 2026
Key Takeaway If your business uses Progress LoadMaster, check for and apply the latest security patch immediately, as this vulnerability is already being actively exploited by attackers.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog after confirming it is being actively exploited by attackers. The flaw, CVE-2026-8037, is a command injection vulnerability in Progress LoadMaster, a widely used load-balancing product. Command injection vulnerabilities like this one are a common and dangerous attack method, as they can allow attackers to run unauthorised commands on affected systems.

While CISA's related directive, BOD 26-04, formally applies only to U.S. federal agencies, the agency encourages all organisations, including small and medium businesses, to adopt the same risk-based approach: prioritise patching vulnerabilities that are known to be exploited in the wild, especially on systems exposed to the internet. Vulnerabilities added to the KEV Catalog are considered high-risk because there is confirmed evidence of real-world attacks, not just theoretical exposure.

Australian businesses using Progress LoadMaster or similar network infrastructure products should check with their IT provider or vendor to confirm whether they are running an affected version and apply available patches as soon as possible. Delaying action on known exploited vulnerabilities significantly increases the risk of compromise.

Summarised by CISO AI from CISA. We link back to every original so you can read it yourself.