← Blog · · df00tech

CISA KEV: Unauthenticated Command Injection in Progress LoadMaster (CVE-2026-8037)

breaking kev Progress CVE-2026-8037

Progress Software has issued a critical security bulletin covering an unauthenticated command injection vulnerability in LoadMaster, its load balancer/ADC appliance, tracked as CVE-2026-8037 (referenced alongside CVE-2026-33691). CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog as of 2026-08-07, indicating active exploitation in the wild.

What was reported

According to Progress, unsanitized input in multiple command endpoints on the LoadMaster appliance allows an attacker to execute arbitrary commands without authentication. No CVSS score has been published in the item provided, and exact exploited endpoints, attacker TTPs, and any ransomware association have not been disclosed — CISA's KEV entry lists exploitation status as "Unknown" for ransomware campaign use.

Why it matters

LoadMaster appliances typically sit at the network edge, fronting production applications and often exposed to the internet by design. An unauthenticated command injection on such a device gives an attacker a direct path to full appliance compromise — potentially enabling traffic interception, pivoting into internal networks, or disruption of load-balanced services. KEV inclusion signals CISA has evidence of real-world exploitation, which raises urgency for any organization running LoadMaster, particularly on internet-facing deployments.

What defenders should do now

  • Inventory all LoadMaster instances (physical, virtual, and cloud) and confirm current firmware/software versions against Progress's advisory.
  • Apply the vendor-supplied patch or mitigation as soon as it is validated in your environment; if patching cannot happen immediately, restrict management/API access to trusted networks only.
  • Review LoadMaster access logs for anomalous requests to command-related endpoints, unexpected process spawns, or configuration changes you did not initiate.
  • Treat any internet-facing LoadMaster appliance as high priority for KEV-driven remediation timelines under applicable directives (e.g., BOD 22-01 for federal agencies; equivalent urgency recommended for others).

This is developing intelligence based on Progress's bulletin and CISA's KEV listing; further technical details, indicators of compromise, and a CVSS score may emerge as the advisory matures. For the authoritative bulletin, see Progress's LoadMaster Critical Security Bulletin.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.