Vulnerability report

Active exploitation observed Confirmed confidence In CISA KEV

CVE-2026-8037

LoadMaster Command Injection

Progress Software / LoadMaster · affected before V7.2.63.2

Severity
CVSS 9.6 · Critical
Confidence
Confirmed
Exploit status
Observed in sensors
EPSS
99.3%
First observed
30 Jun 2026
Last observed
14 Aug 2026

Decision summary

What security teams need to know first

Direct answers before the deeper technical record.

What it is

CVE-2026-8037 is an unauthenticated vulnerability affecting Progress Software LoadMaster and 3 other products. OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an...

Is it exploited?

Yes. KEV Intelligence sensors observed exploitation attempts with confirmed confidence.

Who is affected?

Progress Software / LoadMaster affected before v7.2.63.2.

What should we do?

Patch immediately, validate internet-facing exposure, and monitor for matching requests.

Overview

LoadMaster Command Injection

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints

Vendor Product Affected Status
Progress Software LoadMaster Before V7.2.63.2 Affected
Progress Software LoadMaster Before V7.2.54.18 Affected
Progress Software ECS Connections Manager Before V7.2.63.2 Affected
Progress Software Object Scale Connection Manager Before V7.2.63.2 Affected
Progress Software MOVEit WAF Before V7.2.63.2 Affected
View vendor advisory (opens in new tab)
Published
04 Jun 2026
Exploited Since
30 Jun 2026
Attack vector
Adjacent
Complexity
Low
Privileges
None
User interaction
None

Tags

nuclei_scanner cisa

CVE References

Exploitation evidence

Why KEV Intelligence marks this CVE as exploited

Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.

Exploited in the wild

TheHackerNews

Recorded 01 Jul 2026

Independent exploitation attestation added to the KEV Intelligence record.

Active exploitation observed

KEV Intelligence sensor

First observed 01 Jul 2026

First-party sensor telemetry confirms matching exploitation attempts.

Proof of concept available

GitHub

Recorded 30 Jun 2026

Public scanner or PoC coverage increases practical exploitability.

Known exploited vulnerability sources

Per-source evidence links for KEV attestations are available through the KEV Intelligence Pro API.

Learn about Pro API access
Source Added
TheHackerNews First 2026-07-01 14:51 UTC
KEV Intelligence 2026-07-01 17:30 UTC
The Shadowserver 2026-07-09 00:00 UTC
CISA 2026-08-07 16:45 UTC
CVE 2026-08-07 18:10 UTC

Operational indicators for this CVE are listed under Detection.

Sensor telemetry

First-party evidence of exploitation activity

Aggregate observations show the scale, recency, and distribution of activity without overstating sparse data.

743

Attempts observed

61

Unique attacker IPs

19

Attacker countries

AU · CA · CN · DE · ES · HK · ID · IN · IQ · JP · KR · NL · PK · PL · RO · SG · TR · TW · US

6

Sensors observed

Exploitation attempts over the last 49 days

Daily events observed by KEV Intelligence sensors

Updated 16 Aug 2026

0
3
1
5
612
18
21
13
17
8
88
4
0
0
2
78
10
0
8
2
7
0
15
6
84
81
132
12
16
198
0
6
0
0
0
40
5
0
0
0
0
1
2
13
50
64
1
0
0
29 Jun 9 Jul 19 Jul 29 Jul 16 Aug

First observed 30 Jun 2026 · Last observed 14 Aug 2026

Pro adds sensor region and window summaries. Enterprise adds raw IPs, paths, User-Agents, and payloads.

Request telemetry access

Detection

Operational artifacts and observed signals

Make the evidence actionable in scanner, SOC, and edge-control workflows.

Observed signals

Request targets
3
User-Agents
51

Raw values available in Pro and Enterprise.

Virtual patch status

KEV Intelligence virtual patch guidance is available for this CVE.

AWS WAF Cloudflare ModSecurity

Indicators of Compromise (IoCs)

Operational indicators linked to exploitation of this CVE. IoCs age over time — especially IP addresses.

Type Indicator First Seen Last Seen Age Source
IP 192.42.116.58 2026-06-30 14:53 UTC 2026-06-30 14:53 UTC about 2 months ago Source
IP 192.42.116.105 2026-06-30 14:53 UTC 2026-06-30 14:53 UTC about 2 months ago Source
IP 146.70.139.154 2026-06-30 14:53 UTC 2026-06-30 14:53 UTC about 2 months ago Source

Scanner Artifacts

Scanner and exploit-framework references linked to this CVE.

Virtual Patch Detail

Compensating WAF rules for this CVE.

Available

Enterprise feature. Virtual patch rule content and deployable vendor exports (ModSecurity, Cloudflare, AWS WAF) are available to KEV Intelligence Enterprise users.

Risk and context

Severity, weaknesses, and research context

CVSS v3.1

9.6 Critical
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

EPSS

99.3%

Recent mention · TheHackerNews

Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. The vulnerability,...

Read full advisory

All Mentions

Recent mention · TheHackerNews

Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

TheHackerNews · 08 Aug 2026

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. The vulnerability, tracked as CVE-2026-8037 (CVSS score: 9.6), is a command injection flaw that could be weaponized to achieve arbitrary

Recent mention · TheHackerNews

Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts

TheHackerNews · 01 Jul 2026

A recently disclosed critical security flaw impacting Progress Kemp LoadMaster is seeing active exploitation attempts, according to an advisory from eSentire's Threat Response Unit (TRU). The Canadian cybersecurity company said it identified exploitation attempts targeting CVE-2026-8037 (CVSS score: 9.6), an operating system (OS) command injection flaw that could be exploited to achieve

Recent mention · TheHackerNews

Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth

TheHackerNews · 30 Jun 2026

A critical vulnerability in Progress Kemp LoadMaster can let an unauthenticated attacker execute arbitrary commands as root on the appliance by sending a crafted request to its API. The flaw, tracked as CVE-2026-8037, carries a CVSS score of 9.8 according to ZDI. A patch is available. If you run LoadMaster with the API enabled, update now. Progress published its advisory on June

Recent mention · Watchtower Labs

Enterprise Tech In, Shell Out (Progress Kemp LoadMaster Uninitialized Heap to Pre-Auth RCE CVE-2026-8037)

Watchtower Labs · 29 Jun 2026

Welcome back to another watchTowr Labs blog post.This time, we're looking at Progress Kemp LoadMaster, a load balancer that sits at the edge of a lot of enterprise networks. Edge appliances have a habit of becoming the way in rather than the thing keeping people out, and

Recent mention · Zero Day Initiative Published Advisories

ZDI-26-340: Progress Software Kemp LoadMaster dodelapikey Uninitialized Memory Remote Code Execution Vulnerability

Zero Day Initiative Published Advisories · 09 Jun 2026

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Progress Software Kemp LoadMaster. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-8037.

Recent mention · Zero Day Initiative Published Advisories

ZDI-26-341: Progress Software Kemp LoadMaster dolistapikeys Uninitialized Memory Remote Code Execution Vulnerability

Zero Day Initiative Published Advisories · 09 Jun 2026

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Progress Software Kemp LoadMaster. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-8037.

Recent mention · Zero Day Initiative Published Advisories

ZDI-26-342: Progress Software Kemp LoadMaster apiuser Uninitialized Memory Remote Code Execution Vulnerability

Zero Day Initiative Published Advisories · 09 Jun 2026

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Progress Software Kemp LoadMaster. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2026-8037.

Potential Proof of Concepts

These PoCs are unverified and could contain malware. Use at your own risk.

Timeline

From disclosure to observed exploitation

  1. KEV confirmed by CVE

    Exploitation attested by an external source

  2. Added to CISA KEV

    Listed in the CISA Known Exploited Vulnerabilities catalog

  3. KEV confirmed by The Shadowserver

    Exploitation attested by an external source

  4. Virtual patch available

    Compensating WAF rule available to block exploitation

  5. Public PoC available

    Public proof-of-concept code published

  6. Nuclei template available

    Scanner coverage available

  7. Observed by KEV Intelligence sensors

    Evidence-backed exploitation signal

  8. Added to KEV Intelligence KEV Feed

    High-confidence, third-party attested exploitation

  9. Indicators of compromise added (117)

    Indicators of compromise recorded

  10. CVE published

    Vulnerability disclosed publicly

  11. CVE ID reserved

    Identifier reserved by the CNA

Pro API

Automate this intelligence

Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.

  • Evidence confidence and provenance
  • First-party sensor telemetry
  • PoC and scanner references
  • Affected versions and enrichment
  • Automation-ready JSON delivery

GET /api/v2/pro/kevs/CVE-2026-8037

Free JSON includes basic KEV fields
{
  "cve_id": "CVE-2026-8037",
  "confidence": "Confirmed",
  "cvss_score": 9.6,
  "epss_score": 0.99311,
  "exploit_status": {
    "exploited_in_the_wild": true,
    "active_exploitation_observed": true
  },
  "sensor_telemetry": { "attempts": 743, "sensors": 6 }
}

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.