CISA added CVE-2026-8037 to its Known Exploited Vulnerabilities catalog after reports of active exploitation against Progress Kemp LoadMaster. The flaw, rated CVSS 9.6, is an unauthenticated command injection issue caused by unsanitized input in multiple command endpoints, allowing remote attackers to execute arbitrary commands on vulnerable appliances. CISA’s catalog update increased the total KEV count from 1661 to 1662 and set a remediation deadline of 2026-08-10 for Federal Civilian Executive Branch agencies under Binding Operational Directive 26-04.
Reporting on the exploitation said defenders observed sustained attack activity in the wild, with 792 reported exploit attempts originating from dozens of IP addresses across 18 countries. Prior technical analysis tied the vulnerability to LoadMaster’s escape_quotes() function, while CISA marked known ransomware use as unknown in the KEV entry. The addition places the LoadMaster flaw alongside other recently tracked exploited bugs in products including JetBrains TeamCity, N-able N-central, and Apache Tomcat.

See which actors are running it and whether you're in range.
9 events from the most recent confirmed update back to the earliest known activity.
After adding CVE-2026-8037 to the Known Exploited Vulnerabilities catalog, CISA urged immediate remediation and gave federal agencies three days to patch the exploited Progress LoadMaster flaw. The directive followed confirmation that the unauthenticated command injection bug had been exploited in the wild.
CISA updated its Known Exploited Vulnerabilities Catalog to version 2026.08.07 and added CVE-2026-8037, a Progress LoadMaster command injection vulnerability that allows unauthenticated command execution via unsanitized input in multiple command endpoints. The catalog count increased from 1661 to 1662 entries.
KEVIntel telemetry recorded its last observed exploitation activity targeting CVE-2026-8037 on August 4, 2026, including five exploitation attempts that day. The broader telemetry covered 792 attempts from 65 unique IP addresses across 18 countries over 41 days.
At the end of July 2026, Progress released further LoadMaster security updates that also fixed CVE-2026-33691, a medium-severity vulnerability, alongside the attack-path fix discussed in the article. The vendor said versions prior to the listed patched releases were vulnerable.
Functional proof-of-concept exploit code for CVE-2026-8037 became public on June 29, 2026, increasing the risk of broader abuse of the Progress LoadMaster command injection flaw. The article ties subsequent exploitation attempts to exposed devices after public exploit details were available.
eSentire's Threat Response Unit identified exploitation attempts targeting CVE-2026-8037 beginning on June 29, 2026. The attempts reportedly failed, and eSentire said it detected no post-compromise activity.
Progress Software released security updates in June 2026 to fix CVE-2026-8037 in affected Kemp LoadMaster and MOVEit WAF versions. The flaw allows unauthenticated remote command execution via unsanitized API inputs in multiple command endpoints.
watchTowr Labs published an analysis of the Progress Kemp LoadMaster command injection flaw, linking it to the application's "escape_quotes()" function and improper handling of user-supplied input.
Shadowserver reported that nearly 300 Kemp LoadMaster instances were exposed online amid active exploitation of CVE-2026-8037. It said it was unclear how many of those systems were honeypots or already protected against exploitation.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
11 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecybersecuritynews.com
Open sourcemkd-cirt.mk
Open sourceheise.de
Open sourcethehackernews.com
Open sourcegithub.com
Open sourcecisa.gov
Open sourcecve.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.