
CISA adds exploited Progress LoadMaster command-injection flaw to KEV catalog
CISA added CVE-2026-8037 in Progress LoadMaster to its exploited-vulnerability catalog, giving federal agencies until August 10 to act.
CISA has added CVE-2026-8037, a critical command-injection flaw in Progress LoadMaster, to its Known Exploited Vulnerabilities catalog after finding evidence that attackers are exploiting it in the wild.
The August 7 alert identifies the issue as a Progress LoadMaster command-injection vulnerability and says this class of flaw remains a frequent attack vector for malicious cyber actors. CISA's catalog entry describes the bug as an unauthenticated command-injection issue in Progress LoadMaster that can let an attacker execute arbitrary commands on the appliance through unsanitized input in multiple command endpoints.
Why it matters
Load balancers and application-delivery controllers often sit close to high-value web services, authentication flows, and internal routing paths. That makes a remotely exploitable flaw in this layer more consequential than a routine software bug: compromise can provide a foothold at the edge of an enterprise network and may expose traffic, credentials, or management paths depending on deployment.
NIST's National Vulnerability Database lists the issue as critical, with an NVD CVSS 3.1 base score of 9.8 and a Progress CNA score of 9.6. The NVD description says the flaw affects the API in Progress ADC products and allows an unauthenticated attacker to run arbitrary commands on a LoadMaster appliance by exploiting unsanitized input.
Required action
For U.S. federal civilian agencies, the KEV listing triggers CISA's risk-based remediation process under Binding Operational Directive 26-04. The catalog gives agencies until August 10, 2026, to apply mitigations according to vendor instructions, evaluate internet exposure, and follow CISA's forensics triage expectations where applicable.
Organizations outside the federal government are not legally bound by that directive, but the catalog is widely used as a practical priority list because it tracks vulnerabilities with confirmed exploitation rather than only theoretical severity. Security teams running Progress LoadMaster or related Progress ADC products should verify asset exposure, confirm whether vulnerable versions are present, apply Progress guidance, and review logs for signs of pre-patch compromise.
- CVE: CVE-2026-8037
- Product: Progress LoadMaster
- Weakness: command injection, CWE-77
- CISA KEV date added: August 7, 2026
- Federal due date: August 10, 2026
Sources
Cover photo by Brett Sayles on Pexels, used under the Pexels License.
CyberOGZ Team






Comments (0)
Leave a Comment