The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Progress LoadMaster products, identified as CVE-2026-8037, to its Known Exploited Vulnerabilities (KEV) catalog. This addition mandates that federal agencies address the flaw by August 10, 2026.
The vulnerability is an OS Command Injection Remote Code Execution (RCE) issue, rated with a CVSS score of 9.6. It affects the API in Progress ADC Products and can be exploited by an unauthenticated attacker. By leveraging unsanitized input in multiple command endpoints, an attacker can execute arbitrary commands on the LoadMaster appliance.
Cybersecurity firm eSentire first detected exploitation attempts targeting CVE-2026-8037 beginning on June 29, 2026. While these initial attempts were unsuccessful and no post-compromise activity was observed by eSentire, the presence of a functional Proof-of-Concept (PoC) exploit code, released on the same day, raises concerns about increased exploitation.
Progress initially disclosed the vulnerability on June 4, 2026. The inclusion of CVE-2026-8037 in CISA's KEV catalog signifies that the flaw is actively being exploited in the wild, underscoring the urgency for organizations to apply relevant security patches immediately. Private sector organizations are also strongly advised to review the KEV catalog and prioritize remediation of listed vulnerabilities within their infrastructure.






