The Financial Register.

Inward fraud & financial crime, explained for Gen Z

Live coverage / The Wire

Update · 08:26 pm AEST · 10 August 2026

41 DAYS AGO Key event Share

US agency warns of critical LoadMaster flaw actively exploited in attacks

US agency warns of critical LoadMaster flaw actively exploited in attacks
Photograph: BleepingComputer

The U.S. Cybersecurity and Infrastructure Security Agency has added a critical command injection vulnerability in Progress Kemp LoadMaster to its catalog of actively exploited flaws, ordering federal agencies to patch within three days.

Tracked as CVE-2026-8037, the vulnerability allows unauthenticated attackers to execute arbitrary commands on unpatched LoadMaster appliances through unsanitized API inputs. Progress Software released patches in June for LoadMaster versions GA v7.2.63.1 and older, and LTSF v7.2.54.17 and older. Nearly 300 LoadMaster instances are exposed online, according to threat watchdog Shadowserver, though the number already patched or running as honeypots is unknown.

Kemp LoadMaster is used by over 100,000 deployments worldwide, including Amazon and the U.S. Air Force, to distribute web traffic across multiple servers. "This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise," CISA said. The agency urged all defenders, not just government agencies, to prioritize patching the flaw, Sergiu Gatlan reports for BleepingComputer.

Critical Progress LoadMaster flaw now actively exploited in attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity Progress Kemp LoadMaster command injection vulnerability. bleepingcomputer.com
cybersecurityvulnerabilitycisacritical-vulnerabilitiesus-government

Follow the live coverage →