Critical Progress LoadMaster flaw now actively exploited in attacks

Critical Progress LoadMaster Flaw Now Being Exploited in Real-World Attacks

A critical vulnerability in Progress Kemp LoadMaster, a popular Application Delivery Controller (ADC) and server load balancer used by tech giants and government agencies worldwide, is being actively exploited by hackers. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning, advising all defenders to prioritize patching the flaw as soon as possible.

Kemp LoadMaster is a crucial component in many organizations’ infrastructure, responsible for distributing incoming web traffic across multiple servers, optimizing app performance, and ensuring high service availability. Progress Software claims that 80% of Fortune 500 companies use its products and services, with Kemp LoadMaster boasting over 100,000 deployments worldwide. The vulnerability, tracked as CVE-2026-8037, allows unauthenticated attackers to execute arbitrary commands on unpatched LoadMaster appliances by exploiting unsanitized API inputs in multiple command endpoints.

The issue was first identified in June when Progress Software released security updates to patch the vulnerability in Kemp LoadMaster (GA v7.2.63.1 or older and LTSF v7.2.54.17 or older). However, it’s estimated that nearly 300 Kemp LoadMaster instances are exposed online, leaving them vulnerable to attacks. Shadowserver, an internet threat watchdog, has been monitoring the situation closely.

CISA’s inclusion of CVE-2026-8037 in its catalog of actively exploited vulnerabilities is a stark reminder of the threat posed by this vulnerability. The agency has ordered U.S. Federal Civilian Executive Branch (FCEB) agencies to secure their servers within three days as mandated by Binding Operational Directive 26-04. While BOD 26-04 applies only to U.S. government agencies, CISA urges all defenders to prioritize patching the CVE-2026-8037 vulnerability to block incoming attacks.

This critical flaw is a prime example of why regular security updates and patches are essential in preventing cyber attacks. It’s also a reminder that even seemingly minor vulnerabilities can have significant consequences if left unaddressed. As CISA warned, “this type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.”

To protect your organization from this vulnerability, it’s crucial to apply the latest security patches as soon as possible. This will not only prevent potential attacks but also demonstrate your commitment to maintaining a secure infrastructure. As a best practice, ensure that you regularly test every layer of your environment to identify potential vulnerabilities before attackers do.


Source: Bleeping Computer — 2026-08-10