AI-Generated · tencent/hy3-preview

CISA flags Progress Kemp LoadMaster flaw in KEV after 792 exploitation attempts

CISA added a critical Progress Kemp LoadMaster command injection flaw to its Known Exploited Vulnerabilities catalog after 792 reported exploitation attempts across 18 countries.

CISA added CVE-2026-8037, a critical command injection vulnerability in Progress Kemp LoadMaster with CVSS score 9.6, to its Known Exploited Vulnerabilities catalog on August 8, 2026, following 792 reported exploitation attempts from 65 unique IP addresses across 18 countries over the past 41 days, with federal agencies required to patch by August 10, 2026.

The vulnerability is a critical OS command injection flaw enabling unauthenticated remote code execution, with in-the-wild exploitation starting June 29, 2026, after watchTowr published technical analysis and proof-of-concept code, and federal agencies given three days to patch.

The Known Exploited Vulnerabilities catalog is designed to prioritize flaws with confirmed active exploitation over theoretical high-severity risks, making it a central component of federal vulnerability management frameworks.

The 792 exploitation attempts tracked prior to the KEV addition were spread across 65 unique IP addresses in 18 countries, indicating a broad, distributed campaign rather than a targeted attack against a single organization. The 41-day observation window places the start of mass exploitation attempts roughly in late June, which aligns with the June 29 date reported for the first in-the-wild activity following the watchTowr disclosure.

Federal agencies are required to remediate KEV-listed flaws within strict timelines to limit exposure across government networks, with the August 10 deadline for CVE-2026-8037 falling three days after the catalog addition. CISA has urged all organizations using Progress Kemp LoadMaster, not just federal agencies, to remediate the vulnerability via patching immediately given confirmed active exploitation in the wild.

The high CVSS score of 9.6 reflects the flaw’s severity: unauthenticated remote code execution requires no user interaction or valid credentials to exploit, meaning attackers can compromise vulnerable Progress Kemp LoadMaster systems at scale with minimal effort.

The 792 exploitation attempts logged in just 41 days make CVE-2026-8037 one of the most actively exploited flaws added to the KEV catalog in recent months, a signal that attackers moved quickly to weaponize the public proof-of-concept code after its release.

Sources