US agency warns of critical LoadMaster flaw actively exploited in attacks

The U.S. Cybersecurity and Infrastructure Security Agency has added a critical command injection vulnerability in Progress Kemp LoadMaster to its catalog of actively exploited flaws, ordering federal agencies to patch within three days.
Tracked as CVE-2026-8037, the vulnerability allows unauthenticated attackers to execute arbitrary commands on unpatched LoadMaster appliances through unsanitized API inputs. Progress Software released patches in June for LoadMaster versions GA v7.2.63.1 and older, and LTSF v7.2.54.17 and older. Nearly 300 LoadMaster instances are exposed online, according to threat watchdog Shadowserver, though the number already patched or running as honeypots is unknown.
Kemp LoadMaster is used by over 100,000 deployments worldwide, including Amazon and the U.S. Air Force, to distribute web traffic across multiple servers. "This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise," CISA said. The agency urged all defenders, not just government agencies, to prioritize patching the flaw, Sergiu Gatlan reports for BleepingComputer.