INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Progress LoadMaster flaw Hits CISA Known Exploited Vulnerabilities
| 2026-08-10 09:49 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The Kemp LoadMaster vulnerability is a critical command injection security flaw that enables unauthenticated attackers to execute arbitrary commands on unsanitized API inputs in multiple command endpoints. This has sparked widespread concern among tech companies and government entities worldwide, with many urging patching the CVE-2026-8037 vulnerability to block incoming attacks. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that hackers are exploiting this flaw, while Progress Software has released security updates to patch the vulnerability in its Kemp LoadMaster products. However, there is currently no information available on how many of these vulnerabilities have been exploited or secured against them.
Technical Mitigations AI-generated
* Implement a secure patching strategy for Progress Kemp LoadMaster and MOVEit WAF appliances, with a focus on prioritizing CVE-2026-8037 vulnerability patches.
* Conduct regular security audits and penetration testing to identify and remediate vulnerabilities before they can be exploited by attackers.
* Educate users about the risks associated with command injection attacks and provide training on secure coding practices to prevent exploitation of Progress LoadMaster vulnerabilities.
* Implement a robust incident response plan, including procedures for responding to CVE-2026-8037 attacks, to minimize downtime and ensure business continuity.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-8037CVE-2026-8037
Target & Sectors
FIVE_EYES
FIVE_EYES
governmentgovernment
technologytechnology
Incident Timeline
June 4th
Threat actors attempted to exploit a Progress LoadMaster vulnerability on June 4th.
Click on any entity below to view its context and source!
organisation
PoC
The vulnerability was initially
disclosed
on June 4th and functional Proof-of-Concept (PoC) exploit code was released on June 29th.
June 2026
WatchTowr Labs described the issue as present in a function named "escape_quotes()" within the load balancer application.
June 29th, 2026
Threat actors used exploit tools to target Progress LoadMaster systems.
June 29, 2026
Threat actors used a known vulnerability in the Progress LoadMaster to target their systems.
June 29th
Threat actors attempted to exploit a Progress LoadMaster vulnerability on June 29th.
Click on any entity below to view its context and source!
organisation
PoC
The vulnerability was initially
disclosed
on June 4th and functional Proof-of-Concept (PoC) exploit code was released on June 29th.
2026/07/11
Threat actors used Progress to target ShareFile customers who were using Storage Zone Controllers.
Click on any entity below to view its context and source!
organisation
ShareFile
Last month, Progress also
emailed ShareFile customers
who were using Storage Zone Controllers to immediately shut down servers after identifying what it described at the time as a "credible external security threat" targeting the on-premises secure file-sharing software.
organisation
Storage Zone Controllers
Last month, Progress also
emailed ShareFile customers
who were using Storage Zone Controllers to immediately shut down servers after identifying what it described at the time as a "credible external security threat" targeting the on-premises secure file-sharing software.
August 4, 2026
Threat actors used exploit code to target Progress LoadMaster.
Aug 08, 2026
Threat actors used exploit tools to target Progress LoadMaster systems.
August 10, 2026
Threat actors attempted to exploit the Progress LoadMaster vulnerability.
Click on any entity below to view its context and source!
attribution
FCEB
In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies are recommended to apply the necessary patches by August 10, 2026, to secure their networks in accordance with Binding Operational Directive (BOD) 26-04.
general_metric
26 Binding Operational Directive
In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies are recommended to apply the necessary patches by August 10, 2026, to secure their networks in accordance with Binding Operational Directive (BOD) 26-04.
attribution
Federal Civilian Executive Branch
In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies are recommended to apply the necessary patches by August 10, 2026, to secure their networks in accordance with Binding Operational Directive (BOD) 26-04.
2026/08/10
An unauthenticated attacker exploited unsanitized input in multiple command endpoints of the Progress LoadMaster appliance to execute arbitrary commands on the appliance.
Click on any entity below to view its context and source!
financial
04 BOD
While BOD 26-04 applies only to U.S. government agencies, CISA urged all defenders to prioritize patching the CVE-2026-8037 vulnerability to block incoming attacks.
organisation
LoadMaster
Tracked as
CVE-2026-8037
, this critical command injection security flaw enables unauthenticated attackers to execute arbitrary commands on unpatched LoadMaster appliances by exploiting unsanitized API inputs in multiple command endpoints.
An unauthenticated attacker can trigger the flaw to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints
In early July, cybersecurity firm eSentire observed exploitation attempts targeting CVE-2026-8037.
organisation
API
Tracked as
CVE-2026-8037
, this critical command injection security flaw enables unauthenticated attackers to execute arbitrary commands on unpatched LoadMaster appliances by exploiting unsanitized API inputs in multiple command endpoints.
The
vulnerability
is an OS Command Injection Remote Code Execution issue that resides in API in Progress ADC Products.
organisation
eSentire
An unauthenticated attacker can trigger the flaw to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints
In early July, cybersecurity firm eSentire observed exploitation attempts targeting CVE-2026-8037.
The addition comes a little over a month after eSentire
said
it's seeing active exploitation efforts targeting the flaw, although it noted those efforts were largely unsuccessful.
organisation
eSentire’s Threat Response Unit (TRU
“Beginning on June 29th, 2026, eSentire’s Threat Response Unit (TRU) identified exploitation attempts targeting the critical Progress Kemp LoadMaster vulnerability CVE-2026-8037.
organisation
Progress Kemp LoadMaster
“Beginning on June 29th, 2026, eSentire’s Threat Response Unit (TRU) identified exploitation attempts targeting the critical Progress Kemp LoadMaster vulnerability CVE-2026-8037.
infrastructure
2.63.1
In June, Progress Software
released security updates
to patch the vulnerability in Kemp LoadMaster (GA v7.2.63.1 or older and LTSF v7.2.54.17 or older), and it also confirmed that it impacts
all MOVEit WAF (Web Application Firewall) versions before GA v7.2.63.2
.
infrastructure
2.54.17
In June, Progress Software
released security updates
to patch the vulnerability in Kemp LoadMaster (GA v7.2.63.1 or older and LTSF v7.2.54.17 or older), and it also confirmed that it impacts
all MOVEit WAF (Web Application Firewall) versions before GA v7.2.63.2
.
infrastructure
2.63.2
In June, Progress Software
released security updates
to patch the vulnerability in Kemp LoadMaster (GA v7.2.63.1 or older and LTSF v7.2.54.17 or older), and it also confirmed that it impacts
all MOVEit WAF (Web Application Firewall) versions before GA v7.2.63.2
.
organisation
GA
In June, Progress Software
released security updates
to patch the vulnerability in Kemp LoadMaster (GA v7.2.63.1 or older and LTSF v7.2.54.17 or older), and it also confirmed that it impacts
all MOVEit WAF (Web Application Firewall) versions before GA v7.2.63.2
.
organisation
Kemp LoadMaster
Progress Software says that 80% of Fortune 500 companies use its products and services, with Kemp LoadMaster having over 100,000 deployments worldwide.
organisation
Critical Progress LoadMaster
Critical Progress LoadMaster flaw now actively exploited in attacks.
organisation
BleepingComputer
Days later, the company
released security patches
for a high-severity ShareFile path traversal zero-day vulnerability, but told BleepingComputer that it had "no indication of unauthorized access to any ShareFile customer account or data, and we have not identified any active threat.
organisation
EDR
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
organisation
IP
The attacks originated from the following IP addresses, per the Canadian security vendor -
192.42.116[.]58
192.42.116[.]105
146.70.139[.]154
According to
telemetry data
captured by KEVIntel, a total of 792 exploitation attempts have been observed over the last 41 days from 65 unique IP addresses from 18 countries, including Australia, China, Indonesia, Japan, Poland, and the U.S.
organisation
KEVIntel
The attacks originated from the following IP addresses, per the Canadian security vendor -
192.42.116[.]58
192.42.116[.]105
146.70.139[.]154
According to
telemetry data
captured by KEVIntel, a total of 792 exploitation attempts have been observed over the last 41 days from 65 unique IP addresses from 18 countries, including Australia, China, Indonesia, Japan, Poland, and the U.S.
infrastructure
65 unique IP addresses
The attacks originated from the following IP addresses, per the Canadian security vendor -
192.42.116[.]58
192.42.116[.]105
146.70.139[.]154
According to
telemetry data
captured by KEVIntel, a total of 792 exploitation attempts have been observed over the last 41 days from 65 unique IP addresses from 18 countries, including Australia, China, Indonesia, Japan, Poland, and the U.S.
08, 2026
Threat actors used exploit code to target Progress Kemp LoadMaster.
Click on any entity below to view its context and source!
attribution
Known Exploited
After 792 Reported Exploit Attempts.
Ravie Lakshmanan
Aug 08, 2026
Vulnerability / Network Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday
added
a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild.
tactic
T1588.006 - Vulnerabilities
After 792 Reported Exploit Attempts.
Ravie Lakshmanan
Aug 08, 2026
Vulnerability / Network Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday
added
a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild.
attribution
KEV
After 792 Reported Exploit Attempts.
Ravie Lakshmanan
Aug 08, 2026
Vulnerability / Network Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday
added
a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild.
general_metric
792 exploitation attempts
After 792 Reported Exploit Attempts.
Ravie Lakshmanan
Aug 08, 2026
Vulnerability / Network Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday
added
a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild.
attribution
Vulnerability / Network Security
After 792 Reported Exploit Attempts.
Ravie Lakshmanan
Aug 08, 2026
Vulnerability / Network Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday
added
a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild.
attribution
Progress Kemp LoadMaster
After 792 Reported Exploit Attempts.
Ravie Lakshmanan
Aug 08, 2026
Vulnerability / Network Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday
added
a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild.
Tactical Metrics
Metrics
financial
4
Bod
Click for context!
While BOD 26-04 applies only to U.S. government agencies, CISA urged all defenders to prioritize patching the CVE-2026-8037 vulnerability to block incoming attacks.
Metrics
infrastructure
2.63.1
Software Version
In June, Progress Software
released security updates
to patch the vulnerability in Kemp LoadMaster (GA v7.2.63.1 or older and LTSF v7.2.54.17 or older), and it also confirmed that it impacts
all MOVEit WAF (Web Application Firewall) versions bef…
Metrics
infrastructure
2.54.17
Software Version
…gress Software
released security updates
to patch the vulnerability in Kemp LoadMaster (GA v7.2.63.1 or older and LTSF v7.2.54.17 or older), and it also confirmed that it impacts
all MOVEit WAF (Web Application Firewall) versions before GA v7.2.…
Metrics
infrastructure
2.63.2
Software Version
…Software
released security updates
to patch the vulnerability in Kemp LoadMaster (GA v7.2.63.1 or older and LTSF v7.2.54.17 or older), and it also confirmed that it impacts
all MOVEit WAF (Web Application Firewall) versions before GA v7.2.63.2
.
Metrics
infrastructure
65
Unique Ip Addresses
…According to
telemetry data
captured by KEVIntel, a total of 792 exploitation attempts have been observed over the last 41 days from 65 unique IP addresses from 18 countries, including Australia, China, Indonesia, Japan, Poland, and the U.S.
Intelligence Sources
The Hacker News
2026-08-08
Security Affairs
2026-08-08
BleepingComputer
2026-08-10
Critical Progress LoadMaster flaw now actively exploited in attacks
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-08-11T06:03
Comprehensive Tactical Telemetry
Highly Correlated Entities
17x
attribution
Attributing Entity
Kemp LoadMaster
authority
15x
organisation
Identified Entity
LoadMaster
entity
11x
timeline
Temporal Reference
2026/07/11
date
5x
target region
Target Country
Australia
country
3x
infrastructure
Software Version
2.63.1
version
3x
general metric
%
80
%
2x
tactic
MITRE ATT&CK Technique
T1592.002 - Software
technique
Contextual Telemetry
Context Block
16 METRICS
industry
Targeted Sector
Government
sector
vulnerability
Exploited CVE
CVE-2026-8037
cve
financial
Bod
4
bod
general metric
Cve-2026
8,037
cve-2026
general metric
Fortune
500
fortune
general metric
Deployments
100,000
deployments
general metric
Binding Operational Directive
26
binding operational directive
general metric
Kemp Loadmaster
300
kemp loadmaster
vulnerability
CVSS Score
10
score
tactic
Cyber Operation Type
Remote Code Execution
tactic
general metric
29Th
2,026
29th
source region
Origin Country
Canada
country
general metric
Exploitation Attempts
792
exploitation attempts
infrastructure
Unique Ip Addresses
65
unique ip addresses
general metric
Countries
18
countries
general metric
Vulnerability
10
vulnerability
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.