CVE Tools

CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability

SecurityWeekBy Ionut Arghire

Reported exploitedProgress Kemp LoadMasterMOVEit WAF

Our summary

CISA has added CVE-2026-8037 to its Known Exploited Vulnerabilities catalog after confirming active in-the-wild attacks against Progress Kemp LoadMaster appliances. This critical vulnerability (CVSS 9.6) allows unauthenticated attackers to achieve remote code execution by injecting commands through unsanitized API inputs.

The flaw stems from improper memory initialization in versions prior to 7.2.63.1 for GA and 7.2.54.17 for LTSF releases, affecting other products including MOVEit WAF. Administrators are advised to apply patches immediately to prevent potential compromise of network edge devices.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store