Organizations running Progress Kemp LoadMaster appliances should patch immediately: CISA added the underlying flaw to its Known Exploited Vulnerabilities catalog on Friday, and attack attempts are stacking up. The bug is tracked as CVE-2026-8037 with a CVSS score of 9.6, a command injection hole in the LoadMaster API that lets an unauthenticated attacker run arbitrary commands on the appliance.
The timeline shows why this is urgent. The flaw was disclosed on June 4. A public proof of concept appeared on June 29, and eSentire says it watched exploitation attempts begin the same day. The Hacker News puts the reported attempt count at 792 so far.
CISA orders federal civilian agencies to patch or mitigate by August 10. Private sector operators should read the KEV listing the same way and move LoadMaster and other Progress ADC products to patched releases without delay.
The risk profile is severe because LoadMaster fronts critical applications. An attacker who owns the box can intercept traffic, rewrite responses, and move into the networks behind it. eSentire found the early attempts failed with no post-compromise activity detected, but with a public PoC in circulation, continued scanning is likely.
