CVE Tools

Critical Progress LoadMaster flaw now actively exploited in attacks

BleepingComputerBy Sergiu Gatlan

Reported exploitedProgress Kemp LoadMasterMOVEit WAF

Our summary

CISA has warned that threat actors are actively leveraging a critical command injection vulnerability in Progress Kemp LoadMaster devices. Tracked as CVE-2026-8037, this flaw permits unauthenticated users to execute arbitrary commands by manipulating unsanitized API inputs on specific endpoints.

The issue affects Kemp LoadMaster installations running GA v7.2.63.1 or older, along with LTSF v7.2.54.17 or older, and also impacts all MOVEit WAF versions before GA v7.2.63.2. Progress Software released fixes in June, and recent analysis by Shadowserver indicates that nearly 300 instances remain exposed online. CISA has added the CVE to its Known Exploited Vulnerabilities catalog, requiring US federal agencies to remediate the risk within three days under Binding Operational Directive 26-04.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store