VYPR
kevPublished Aug 7, 2026· 1 source

CISA Adds Progress LoadMaster Command Injection Vulnerability to KEV Catalog

CISA has added CVE-2026-8037, a command injection vulnerability in Progress LoadMaster, to its Known Exploited Vulnerabilities (KEV) Catalog, citing active exploitation.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has officially added CVE-2026-8037 to its Known Exploited Vulnerabilities (KEV) Catalog. This designation signifies that the vulnerability, which affects Progress LoadMaster products, has been actively exploited by malicious actors in the wild. The inclusion in the KEV Catalog mandates that federal civilian executive branch agencies prioritize the remediation of this vulnerability on any publicly exposed assets.

The vulnerability, identified as a command injection flaw, allows attackers to execute arbitrary commands on affected systems. This type of vulnerability is a common and potent attack vector, enabling threat actors to gain unauthorized access, escalate privileges, and potentially take full control of compromised systems. The active exploitation observed by CISA underscores the immediate threat posed by CVE-2026-8037.

Federal agencies are bound by Binding Operational Directive (BOD) 26-04, which requires them to manage vulnerabilities based on risk. This directive specifically emphasizes the importance of the KEV Catalog, compelling agencies to rapidly patch vulnerabilities listed therein, particularly those that grant complete control of an asset post-exploitation. The directive also outlines requirements for agencies to check for signs of compromise before applying patches.

While BOD 26-04 specifically targets Federal Civilian Executive Branch (FCEB) agencies, CISA strongly encourages all organizations, including private sector entities, to adopt a risk-based approach to vulnerability management. Prioritizing the remediation of vulnerabilities listed in the KEV Catalog is a crucial step in bolstering an organization's security posture against known, actively exploited threats.

CISA continues to monitor the threat landscape and will add new vulnerabilities to the KEV Catalog as they are identified and meet the established criteria. These criteria include the existence of a CVE ID, concrete evidence of active exploitation, and clear guidance on mitigation or patching.

Organizations that are aware of exploited vulnerabilities not yet listed in the KEV Catalog are encouraged to submit them for consideration through CISA's KEV Nomination Form. This collaborative effort helps ensure that the catalog remains a comprehensive and up-to-date resource for identifying and prioritizing the most critical cybersecurity risks.

The addition of CVE-2026-8037 to the KEV Catalog serves as a stark reminder of the persistent threat posed by unpatched vulnerabilities and the importance of proactive security measures. Organizations must remain vigilant in their vulnerability management programs to defend against evolving cyber threats.

Synthesized by Vypr AI