🔴 Critical  |  Source: The Hacker News


A critical command injection vulnerability (CVE-2026-8037, CVSS 9.6) in Progress Kemp LoadMaster has been added to CISA’s Known Exploited Vulnerabilities catalogue following nearly 800 confirmed exploitation attempts in the wild. LoadMaster is a widely deployed application delivery controller and load balancer used across enterprise and cloud environments. The flaw allows attackers to execute arbitrary commands, potentially leading to full system compromise.

Security Architect’s Take: Patch Progress Kemp LoadMaster immediately if deployed in your environment, and audit internet-facing instances for signs of compromise — prioritise any LoadMaster nodes sitting at the perimeter or in front of critical workloads. If patching cannot be applied immediately, restrict management interface access to trusted IP ranges and review firewall rules to limit exposure.

Original advisory: Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts