Critical Progress LoadMaster flaw now actively exploited in attacks

Critical Progress LoadMaster Flaw Exposed to Hackers Worldwide

A severe security vulnerability in the popular Application Delivery Controller (ADC) and server load balancer, Kemp LoadMaster, has been actively exploited by hackers. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that this critical command injection flaw can allow unauthenticated attackers to execute arbitrary commands on unpatched appliances, putting thousands of organizations worldwide at risk.

Kemp LoadMaster is used by major tech companies and government entities to distribute incoming web traffic across multiple servers, optimize app performance, and ensure high service availability. Progress Software, the company behind Kemp LoadMaster, claims that 80% of Fortune 500 companies use its products and services, with over 100,000 deployments worldwide. This widespread adoption makes the vulnerability a significant concern for security teams.

The flaw, tracked as CVE-2026-8037, allows hackers to inject malicious commands through unsanitized API inputs in multiple command endpoints. Progress Software released security updates in June to patch the vulnerability, but it’s unclear how many organizations have applied the fixes. In fact, nearly 300 Kemp LoadMaster instances are exposed online, according to threat watchdog Shadowserver, leaving them vulnerable to attacks.

The CISA has added the flaw to its catalog of actively exploited vulnerabilities and ordered U.S. Federal Civilian Executive Branch (FCEB) agencies to secure their servers within three days. While this directive applies only to U.S. government agencies, CISA urged all defenders to prioritize patching the CVE-2026-8037 vulnerability to block incoming attacks.

This type of vulnerability is a common attack vector for malicious cyber actors and poses significant risks to organizations worldwide. The fact that hackers are already exploiting it highlights the need for swift action by security teams. By patching this vulnerability, organizations can prevent attackers from executing arbitrary commands on their systems and protect sensitive data.

For those responsible for securing networks, this serves as a reminder of the importance of proactive threat hunting and patch management. With thousands of vulnerable instances exposed online, it’s crucial to prioritize updates and ensure that all layers of defense are tested regularly to detect potential threats before they cause harm.


Source: Bleeping Computer — 2026-08-10