Threat Intelligence

Critical Flaw in Progress Kemp LoadMaster Added to US Government's Actively Exploited Vulnerabilities List

The Hacker News · 8 Aug 2026
Key Takeaway If your business uses Progress Kemp LoadMaster, check for and apply the latest security patches immediately, as this vulnerability is being actively exploited by attackers.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical-severity vulnerability in Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog after confirming active exploitation attempts in the wild. The flaw, tracked as CVE-2026-8037, carries a near-maximum CVSS severity score of 9.6 and is a command injection vulnerability that could allow attackers to execute arbitrary commands on affected systems.

Progress Kemp LoadMaster is a load balancing and application delivery solution used by organisations to manage network traffic and ensure application availability. Because load balancers often sit at the edge of a network handling incoming traffic, vulnerabilities in these systems can give attackers a foothold to compromise internal networks, steal data, or disrupt operations. The inclusion in CISA's KEV catalog signals that real-world attacks exploiting this flaw have already been detected, making it a priority for immediate remediation.

While the KEV catalog primarily drives mandatory patching requirements for U.S. federal agencies, it also serves as an important early warning for private businesses worldwide, including Australian small and medium enterprises using affected Progress Kemp products. Organisations running LoadMaster should check for available patches and apply them as soon as possible to reduce their exposure to this actively exploited threat.

CISA KEV Progress Kemp LoadMaster vulnerability management command injection network security

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.