Breaking
SecurityConfirmed

Flaw in Progress LoadMaster exploited in attacks

CISA warns of active exploitation of critical command injection flaw in Progress Kemp LoadMaster; urges patching.

··6 hours ago·3 min read
a computer generated image of a computer
Photo by Growtika on Unsplash

Federal agencies are being ordered to patch a critical vulnerability in Progress Software's Kemp LoadMaster after U.S. cybersecurity officials confirmed hackers are actively exploiting it in attacks.

Kemp LoadMaster, an application delivery controller and server load balancer used by major tech companies and government entities worldwide—including Amazon and the U.S. Air Force—is the target of a command injection flaw that could let unauthenticated attackers run arbitrary commands on vulnerable appliances.

The Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability, tracked as CVE-2026-8037, to its catalog of actively exploited flaws on Friday, triggering a mandate for federal civilian agencies to patch within three days.

Critical Command Injection Vulnerability

The vulnerability is a command injection issue, meaning unsanitized API inputs in multiple command endpoints allow attackers to inject and execute arbitrary commands. The flaw is rated critical severity, underscoring the risk it poses to unpatched systems.

Progress Software, which owns Kemp LoadMaster, released security updates in June to patch the flaw. The updates cover Kemp LoadMaster versions GA v7.2.63.1 and older, as well as LTSF v7.2.54.17 and older. The company also confirmed that all MOVEit WAF (Web Application Firewall) versions before GA v7.2.63.2 are affected, expanding the scope of the advisory.

According to Progress Software, 80% of Fortune 500 companies use its products and services, with Kemp LoadMaster having over 100,000 deployments worldwide. This scale gives a sense of the potential exposure.

Exploitation Confirmed, Instances Exposed

Internet watchdog Shadowserver reports that nearly 300 Kemp LoadMaster instances are exposed online. However, it's unclear how many of these are honeypots or have already been secured against CVE-2026-8037 attacks.

The number of exposed instances is relatively small compared to the total deployments, but the critical nature of the vulnerability and its active exploitation make every unpatched system a priority.

CISA Order, Federal Directive

CISA's addition of the flaw to its Known Exploited Vulnerabilities catalog triggers a mandate for U.S. Federal Civilian Executive Branch (FCEB) agencies to secure their servers within three days, as required by Binding Operational Directive 26-04.

The advisory stresses the risk to federal systems. "This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise," the agency warned.

While the directive applies only to government agencies, CISA urged all defenders to prioritize patching CVE-2026-8037 to block incoming attacks.

Broader Context of Progress Incidents

This is not the first security issue Progress Software has faced recently. Last month, the company emailed ShareFile customers using Storage Zone Controllers to immediately shut down servers after identifying what it described at the time as a "credible external security threat" targeting the on-premises secure file-sharing software.

Days later, Progress released security patches for a high-severity ShareFile path traversal zero-day vulnerability. However, the company told BleepingComputer that it had "no indication of unauthorized access to any ShareFile customer account or data, and we have not identified any active threat."

These incidents highlight the ongoing challenges faced by organizations that rely on Progress products for critical infrastructure.

Recommendations for Defenders

Organizations using Kemp LoadMaster or MOVEit WAF should apply the available security updates immediately. For Kemp LoadMaster, the fixes are in GA v7.2.63.1 (or newer) and LTSF v7.2.54.17 (or newer). MOVEit WAF users need to upgrade to GA v7.2.63.2 or later.

Administrators should also review their network exposure, as Shadowserver data indicates a significant number of LoadMaster instances are reachable from the internet. Reducing exposure can limit the attack surface.

CISA's directive underscores the urgency. While the three-day deadline applies to federal agencies, all defenders should treat this as a high-priority fix.

Why It Matters

Active exploitation of a critical flaw in a widely used load balancer is a serious concern for any organization relying on Kemp LoadMaster for application delivery. The fact that CISA had to issue a binding directive suggests the threat is immediate and credible.

The vulnerability allows unauthenticated attackers to execute commands, which could lead to full system compromise, data theft, or disruption of services. Given that LoadMaster is often placed in front of critical applications, a successful exploit could have cascading effects on business operations.

This incident also serves as a reminder that even established vendors can have critical vulnerabilities, and the window between disclosure and exploitation can be short. Defenders must stay vigilant and patch promptly.

#cve-2026-8037#progress software#kemp loadmaster#cisa#command injection

Sources

Iliyas

Editor, Xploitwire

This article was researched and drafted through our automated editorial pipeline from the sources listed above, then checked against those sources through our automated fact-check process, under the editorial policies set by Iliyas. Our Automation Policy →

← Back to all stories