The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity Progress Kemp LoadMaster command injection vulnerability. Kemp LoadMaster is a very popular Application Delivery Controller (ADC) and server load balancer used by tech companies and government entities worldwide (e.g., Amazon, U.S. Air Force) to distribute incoming web traffic across multiple servers, optimize app performance, and ensure high service availability. Progress Software says that 80% of Fortune 500 companies use its products and services, with Kemp LoadMaster having over 100,000 deployments worldwide. Tracked as CVE-2026-8037, this critical command injection security flaw enables unauthenticated attackers to execute arbitrary commands on unpatched LoadMaster appliances by exploiting unsanitized API inputs in multiple command endpoints. In June, Progress Software released security updates to patch the vulnerability in Kemp LoadMaster (GA v7.2.63.1 or older and LTSF v7.2.54.17 or older), and it also confirmed that it impacts all MOVEit WAF (Web Application Firewall) versions before GA v7.2.63.2. According to Internet threat watchdog Shadowserver, nearly 300 Kemp LoadMaster instances are exposed online. However, there is no information regarding how many of them are honeypots or have already been secured against CVE-2026-8037 attacks. On Friday, CISA added the flaw to its catalog of actively exploited vulnerabilities, ordering U.S. Federal Civilian...
Critical Progress LoadMaster flaw now actively exploited in attacks
BleepingComputer
·Sergiu Gatlan
·Published Aug 10, 2026
·Updated
Affected Software
2 affected components
Progress Software Kemp LoadMaster<7.2.63.2, <=7.2.63.1, <=7.2.54.17
Progress Software MOVEit WAF (Web Application Firewall)<7.2.63.2
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a critical command injection vulnerability in Progress Kemp LoadMaster that is being actively exploited by hackers.
2
What security implications are discussed in the article?
The article highlights the risks associated with the exploitation of the critical-severity vulnerability in LoadMaster, which could lead to unauthorized access and control of affected systems.
3
What products or software are affected by the vulnerability?
The vulnerability affects Progress Software Kemp LoadMaster and Progress Software MOVEit WAF.
4
What action has CISA taken regarding the vulnerability?
CISA has issued a warning about the exploitation of the critical-severity vulnerability in LoadMaster.
5
When was the vulnerability first reported as being exploited?
The vulnerability was reported as being actively exploited on August 10, 2026.