# CISA Flags Progress Kemp LoadMaster Command Injection After 792 Exploit Attempts in the Wild
## The Threat
Progress Kemp LoadMaster has a command injection vulnerability that's no longer theoretical — CISA added it to the Known Exploited Vulnerabilities catalog on Friday after researchers documented nearly 800 exploitation attempts against exposed instances. The flaw, CVE-2026-8037, carries a CVSS score of 9.6, and for good reason: command injection at the network perimeter, on the device managing traffic into your environment, is about as bad as it gets.
LoadMaster is Progress Software's application delivery controller — a load balancer and traffic management appliance used across enterprise networks, healthcare systems, financial institutions, and government agencies to route and secure inbound application traffic. Compromising it doesn't just expose one server; it gives an attacker a privileged vantage point at the edge of the network, upstream of everything the appliance is protecting.
The command injection flaw allows an attacker to pass malicious input through an interface that the appliance fails to sanitize, executing arbitrary OS-level commands on the underlying system. With 792 reported exploitation attempts already logged before the KEV listing, this is not a vulnerability defenders have the luxury of scheduling for the next patch window.
## Severity and Impact
| Field | Detail |
|---|---|
| CVE | CVE-2026-8037 |
| CVSS Score | 9.6 (Critical) |
| Vulnerability Type | Command Injection |
| CWE | CWE-77 (Improper Neutralization of Special Elements used in a Command) |
| Attack Vector | Network |
| Attack Complexity | Low |
| Authentication Required | Low / None (verify against vendor advisory) |
| CISA KEV Added | August 8, 2026 |
| Known Exploitation | Yes — 792 attempts reported |
The near-perfect CVSS score reflects both the accessibility of the attack (no exotic prerequisites) and the severity of impact. Arbitrary command execution on a network load balancer means an attacker can pivot, intercept traffic, inject responses, or disable availability controls entirely.
## Affected Products
Organizations running LoadMaster in high-availability pairs should patch both nodes; a compromised active node in an HA pair undermines the security posture of the standby as well.
## Mitigations
Immediate actions:
If patching is not immediately possible:
Federal civilian agencies are subject to CISA's BOD 22-01 directive and face a mandatory remediation deadline — check the KEV catalog entry for the specific due date.
## References
---
## HackWire Analysis
The 792 exploitation attempts logged before CISA pulled the trigger on a KEV listing tell a story that's becoming grimly familiar: by the time a critical network appliance vulnerability gets official confirmation, the attacker community has already been at it for days.
What makes LoadMaster specifically dangerous is its deployment context. This is not a web app sitting in a DMZ — it's the device that *is* the perimeter for many organizations. Security teams configure it to enforce TLS termination, WAF rules, and traffic policies. Getting code execution on it is equivalent to owning the lobby and the security desk simultaneously. Everything behind it is downstream of a compromised trust anchor.
The broader pattern here is impossible to ignore. Over the past two years, CISA's KEV catalog has been disproportionately weighted toward network appliances and edge devices: Ivanti Connect Secure, Palo Alto GlobalProtect, Cisco ASA, Fortinet FortiGate. These aren't coincidental targets — they're strategically attractive precisely because they sit at the intersection of high privilege and frequent internet exposure. Threat actors, including nation-state groups, have made a cottage industry of chaining appliance exploits into full enterprise compromises.
For defenders, the calculus here is stark. If you're running LoadMaster and haven't restricted management interface access to a dedicated out-of-band network, you have a pre-existing misconfiguration problem that this CVE just weaponized. The patch matters. The architecture matters more. Assume that any LoadMaster instance with a publicly reachable management interface that hasn't been patched by end of business today has been probed. The 792-attempt figure is what was *reported* — the actual scan volume across the internet is likely far higher.
Healthcare and financial services organizations running LoadMaster for application delivery should treat this as an incident response trigger, not a routine patch cycle.
— HackWire Editorial
---
## Related Coverage