CVE Tools

Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

The Hacker NewsBy The Hacker News

Reported exploitedProgress Kemp LoadMaster

Our summary

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity command injection vulnerability in Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog. The flaw, CVE-2026-8037 (CVSS score: 9.6), allows unauthenticated attackers to execute arbitrary code remotely. It follows reports of over 792 exploitation attempts from 65 IP addresses across 18 countries between July 16 and August 4, 2026. CISA urges immediate patching by FCEB agencies to comply with BOD 26-04.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store