Technology News

Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

The U.S. Cybersecurity and Infrastructure Security Agency added a critical‑severity command injection flaw in Progress Kemp LoadMaster to its Known Exploited Vulnerabilities catalog after 792 active exploitation attempts were reported.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical‑severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild.

The vulnerability, tracked as CVE-2026-8037 with a CVSS score of 9.6, is a command injection flaw that could be weaponized to achieve arbitrary command execution on affected systems.

Progress Kemp LoadMaster is a load‑balancing appliance widely deployed in enterprise networks to distribute traffic across application servers.

In a public statement, the vendor confirmed that the flaw allows attackers to inject shell commands through the web‑based management interface.

Patch version 2.5.1 was released by Progress on March 15, 2026, and the vendor urged customers to apply the update immediately.

Security researchers reported 792 separate exploitation attempts targeting the vulnerability since its discovery, with attackers attempting to gain remote code execution on target hosts.

Organizations that rely on LoadMaster for critical services are advised to verify that the latest firmware is installed and to restrict management‑interface access to trusted IP ranges.

CISA recommends that affected customers monitor logs for anomalous command‑execution attempts and to apply the vendor patch as a priority.

Additional mitigations include disabling unused HTTP methods, enforcing least‑privilege access for the management interface, and reviewing firewall rules to block traffic to the vulnerable endpoint.

Given the high severity score and the volume of exploitation attempts, the addition of this flaw to the KEV catalog underscores the importance of timely patching and rigorous network segmentation.

Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Frid…

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Frid…

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical‑severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild.

The vulnerability, tracked as CVE-2026-8037 with a CVSS score of 9.6, is a command injection flaw that could be weaponized to achieve arbitrary command execution on affected systems.

Progress Kemp LoadMaster is a load‑balancing appliance widely deployed i…

Progress Kemp LoadMaster is a load‑balancing appliance widely deployed i…

Progress Kemp LoadMaster is a load‑balancing appliance widely deployed in enterprise networks to distribute traffic across application servers.

In a public statement, the vendor confirmed that the flaw allows attackers to inject shell commands through the web‑based management interface.

Patch version 2.5.1 was released by Progress on March 15, 2026, and the…

Patch version 2.5.1 was released by Progress on March 15, 2026, and the…

Patch version 2.5.1 was released by Progress on March 15, 2026, and the vendor urged customers to apply the update immediately.

Security researchers reported 792 separate exploitation attempts targeting the vulnerability since its discovery, with attackers attempting to gain remote code execution on target hosts.

Organizations that rely on LoadMaster for critical services are advised…

Organizations that rely on LoadMaster for critical services are advised…

Organizations that rely on LoadMaster for critical services are advised to verify that the latest firmware is installed and to restrict management‑interface access to trusted IP ranges.

CISA recommends that affected customers monitor logs for anomalous command‑execution attempts and to apply the vendor patch as a priority.

Additional mitigations include disabling unused HTTP methods, enforcing…

Additional mitigations include disabling unused HTTP methods, enforcing…

Additional mitigations include disabling unused HTTP methods, enforcing least‑privilege access for the management interface, and reviewing firewall rules to block traffic to the vulnerable endpoint.

Given the high severity score and the volume of exploitation attempts, the addition of this flaw to the KEV catalog underscores the importance of timely patching and rigorous network segmentation.