CISA flags Progress Kemp LoadMaster flaw in KEV after 792 exploitation attempts
CISA added a critical Progress Kemp LoadMaster command injection flaw to its Known Exploited Vulnerabilities catalog after 792 reported exploitation attempts across 18 countries.
The Known Exploited Vulnerabilities catalog is designed to prioritize flaws with confirmed active exploitation over theoretical high-severity risks, making it a central component of federal vulnerability management frameworks.
The 792 exploitation attempts tracked prior to the KEV addition were spread across 65 unique IP addresses in 18 countries, indicating a broad, distributed campaign rather than a targeted attack against a single organization. The 41-day observation window places the start of mass exploitation attempts roughly in late June, which aligns with the June 29 date reported for the first in-the-wild activity following the watchTowr disclosure.
Federal agencies are required to remediate KEV-listed flaws within strict timelines to limit exposure across government networks, with the August 10 deadline for CVE-2026-8037 falling three days after the catalog addition. CISA has urged all organizations using Progress Kemp LoadMaster, not just federal agencies, to remediate the vulnerability via patching immediately given confirmed active exploitation in the wild.
The high CVSS score of 9.6 reflects the flaw’s severity: unauthenticated remote code execution requires no user interaction or valid credentials to exploit, meaning attackers can compromise vulnerable Progress Kemp LoadMaster systems at scale with minimal effort.
The 792 exploitation attempts logged in just 41 days make CVE-2026-8037 one of the most actively exploited flaws added to the KEV catalog in recent months, a signal that attackers moved quickly to weaponize the public proof-of-concept code after its release.