<- ALL CYBER NEWS

Critical

Progress, Kemp LoadMaster, Load Balancer, CVE-2026-8037, CISA KEV, RCE

Kemp LoadMaster CVE-2026-8037 Exploited, in CISA KEV

Progress Kemp LoadMaster CVE-2026-8037 (CVSS 9.6 unauth RCE) is in CISA KEV after 792 exploit attempts. Fix, EPSS, and mitigation.

Progress Kemp LoadMaster CVE-2026-8037 Is in CISA KEV After 792 Exploit Attempts

Progress Kemp LoadMaster CVE-2026-8037, an unauthenticated command-injection flaw rated CVSS 9.6, has been added to CISA's Known Exploited Vulnerabilities catalog after active exploitation in the wild. The bug lets an attacker with no credentials run arbitrary commands on the load-balancer appliance through unsanitized input in multiple command endpoints, and telemetry recorded 792 exploitation attempts over 41 days from 65 IP addresses across 18 countries. Patch to a fixed Progress release now and restrict the management interface to trusted IPs. CISA listed the flaw on August 8, 2026, and its EPSS score sits at the 99.9th percentile, among the highest exploitation-likelihood ratings possible.

The root cause is a familiar one made worse by where it lives. watchTowr Labs traced the flaw to a function named escape_quotes() in the LoadMaster application that mishandles user-supplied input, turning a quoting routine into a command-injection primitive (CWE-77). Because a load balancer sits at the network edge, in front of the applications it protects, unauthenticated code execution on the appliance is a foothold with a view of everything behind it. That combination, edge-facing plus pre-authentication plus arbitrary command execution, is why a 9.6 here behaves like a top-priority incident rather than a routine patch.

The exploitation data is what removes any room for delay. eSentire reported active attempts a little over a month before the KEV listing, originating from 192.42.116.58, 192.42.116.105, and 146.70.139.154, and characterized most of those early efforts as unsuccessful. Since then, KEVIntel telemetry counted 792 attempts from 65 unique addresses in 18 countries. Whether or not a given probe landed, that volume means automated scanning has fully locked onto the flaw, and any exposed appliance is being tested continuously.

How urgent is CVE-2026-8037, and can I mitigate without downtime?

It is patch-now urgent: it is in KEV, it is unauthenticated RCE on an edge device, and its EPSS is at the 99.9th percentile. Apply the fixed Progress LoadMaster release as the primary fix. If you cannot patch immediately, the effective interim control is to restrict the management interface and API to trusted administrative IP ranges with firewall rules or ACLs, and to disable API access where it is not required, which removes the reachable attack surface until you can update. Neither workaround replaces the patch.

How do I tell if my LoadMaster was targeted?

Confirm exposure first by checking whether the appliance's web UI and API are reachable from untrusted networks. Then audit HTTP access logs for requests to the command endpoints carrying shell metacharacters such as ;, |, backticks, or $(...), and review for signs of post-exploitation such as unexpected webshells or SSH keys added to privileged accounts. Block the eSentire-reported source IPs and feed them to your detection tooling.

Detail

Value

CVE

CVE-2026-8037

Severity

CVSS 9.6, unauthenticated command injection (CWE-77)

EPSS

99.3% probability, 99.9th percentile

Status

In CISA KEV (Aug 8, 2026); active exploitation

Telemetry

792 attempts, 41 days, 65 IPs, 18 countries

Root cause

escape_quotes() mishandling (per watchTowr)

Fix

Update to fixed Progress LoadMaster release; restrict mgmt interface

Our read

Continuous verification is the whole point of an edge like this. A load balancer is a control you place in the path of your traffic to enforce policy, and the moment it can be commandeered without credentials it becomes the softest way in rather than a guard. Our analysis of CISA's 2025 KEV data found that 67% of the year's actively exploited vulnerabilities would have been missed by a once-a-year pentest, and an edge appliance being probed 792 times in six weeks is exactly why point-in-time testing is not enough for internet-facing infrastructure. KEV membership plus a 99.9th-percentile EPSS is about as clear a prioritization signal as this field produces. Patch, lock the management plane to trusted IPs, and verify exposure continuously rather than annually.

Reporting by The Hacker News; exploitation telemetry and root-cause details per CISA KEV, watchTowr Labs, eSentire, and KEVIntel. Sources linked above.

Related: F5 NGINX CVE-2026-42533 unauthenticated heap overflow · Arista VeloCloud CVE-2026-16812 zero-day

Liked this briefing? Share it:

More briefings

Related posts appear on the live page
Get the briefings first
Breaking security news, verified fast, with the one fact the headlines skip. No spam - unsubscribe anytime.