CYBER WIRE
What Day is Today in Cyber?

CVE-2026-8037: Progress LoadMaster is being actively exploited

On the CISO triangle · Technology

CISA KEV Actively exploited · unauthenticated · remediate in 3 days

While the board deck was being polished, something in the infrastructure was being exploited.

What CISA flagged

CISA has added CVE-2026-8037 to its Known Exploited Vulnerabilities (KEV) catalog. It is an unauthenticated command-injection flaw in Progress (Kemp) LoadMaster, per reporting from BleepingComputer. Federal civilian agencies are directed to remediate it within three days, the compressed clock CISA reserves for vulnerabilities under active attack.

~300 still exposed

Shadowserver data cited in the reporting puts roughly 300 LoadMaster instances still reachable on the public internet. LoadMaster sits in front of applications as a load balancer, exactly the kind of edge box that turns one unauthenticated bug into a foothold.

What to actually do, today, not next quarter:

  • Find them. Inventory every internet-facing LoadMaster, including the ones nobody remembers owning.
  • Patch or mitigate. Apply the vendor fix; restrict the management interface off the public internet.
  • Assume nothing. Hunt for signs of exploitation before you close the ticket.

Sources · BleepingComputer, CISA warns of critical Progress LoadMaster flaw exploited in attacks ↗  ·  CISA KEV catalog ↗

← All dispatches