VYPR
kevPublished Aug 7, 2026· Updated Aug 20, 2026· 5 sources

CISA Adds Progress LoadMaster Command Injection Vulnerability to KEV Catalog

CISA has added CVE-2026-8037, a command injection vulnerability in Progress LoadMaster, to its Known Exploited Vulnerabilities (KEV) Catalog, citing active exploitation.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has officially added CVE-2026-8037 to its Known Exploited Vulnerabilities (KEV) Catalog. This designation signifies that the vulnerability, which affects Progress LoadMaster products, has been actively exploited by malicious actors in the wild. The inclusion in the KEV Catalog mandates that federal civilian executive branch agencies prioritize the remediation of this vulnerability on any publicly exposed assets.

The vulnerability, identified as a command injection flaw, allows attackers to execute arbitrary commands on affected systems. This type of vulnerability is a common and potent attack vector, enabling threat actors to gain unauthorized access, escalate privileges, and potentially take full control of compromised systems. The active exploitation observed by CISA underscores the immediate threat posed by CVE-2026-8037.

Federal agencies are bound by Binding Operational Directive (BOD) 26-04, which requires them to manage vulnerabilities based on risk. This directive specifically emphasizes the importance of the KEV Catalog, compelling agencies to rapidly patch vulnerabilities listed therein, particularly those that grant complete control of an asset post-exploitation. The directive also outlines requirements for agencies to check for signs of compromise before applying patches.

While BOD 26-04 specifically targets Federal Civilian Executive Branch (FCEB) agencies, CISA strongly encourages all organizations, including private sector entities, to adopt a risk-based approach to vulnerability management. Prioritizing the remediation of vulnerabilities listed in the KEV Catalog is a crucial step in bolstering an organization's security posture against known, actively exploited threats.

CISA continues to monitor the threat landscape and will add new vulnerabilities to the KEV Catalog as they are identified and meet the established criteria. These criteria include the existence of a CVE ID, concrete evidence of active exploitation, and clear guidance on mitigation or patching.

Organizations that are aware of exploited vulnerabilities not yet listed in the KEV Catalog are encouraged to submit them for consideration through CISA's KEV Nomination Form. This collaborative effort helps ensure that the catalog remains a comprehensive and up-to-date resource for identifying and prioritizing the most critical cybersecurity risks.

The addition of CVE-2026-8037 to the KEV Catalog serves as a stark reminder of the persistent threat posed by unpatched vulnerabilities and the importance of proactive security measures. Organizations must remain vigilant in their vulnerability management programs to defend against evolving cyber threats.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has officially added Progress Kemp LoadMaster vulnerability CVE-2026-8037 to its Known Exploited Vulnerabilities (KEV) catalog. This critical flaw, rated 9.6 by CVSS, allows for command injection and arbitrary code execution. Telemetry data indicates 792 exploitation attempts have been observed from 65 unique IP addresses across 18 countries in the past 41 days, with the most recent activity logged on August 4, 2026.

CISA has now urged federal agencies to immediately patch CVE-2026-8037, a critical OS command injection vulnerability in Progress LoadMaster load balancers that has been exploited in the wild. The agency's inclusion of the flaw in its Known Exploited Vulnerabilities (KEV) catalog mandates a three-day patching window for government entities, highlighting the urgency of the threat.

The article provides further details on the exploitation of CVE-2026-8037, noting that public exploit code was released on June 29, 2026, shortly before threat actors began scanning for and attempting to exploit vulnerable Progress LoadMaster appliances. Hundreds of exploitation attempts have been reported from multiple countries, indicating widespread active scanning following the release of exploit code.

CISA has added two new vulnerabilities affecting TrueConf Server, CVE-2026-72529 and CVE-2026-72530, to its Known Exploited Vulnerabilities (KEV) Catalog. These vulnerabilities, a missing authentication flaw and a code injection flaw, are being actively exploited in the wild. Federal agencies are now required to prioritize patching these vulnerabilities on public-facing assets as per Binding Operational Directive (BOD) 26-04.

Synthesized by Vypr AI