The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability affecting the Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) list. This update follows numerous reports of active exploitation in the field, highlighting the urgency for organizations to address this issue.
Details of the Critical Vulnerability
Identified as CVE-2026-8037, the vulnerability has been assigned a CVSS score of 9.6, indicating its severe nature. It is characterized as a command injection flaw that allows unauthorized attackers to execute arbitrary commands on affected devices.
CISA has indicated that the vulnerability exists due to unsanitized input in several command endpoints, which can be exploited by attackers to run commands without authentication. The flaw originates from a function in the load balancer application known as “escape_quotes()”, as detailed in a June 2026 analysis by watchTowr Labs.
Exploitation Attempts and Observations
While exploitation attempts have been noted, security firm eSentire has reported that many of these efforts have not been successful. The attacks have been traced back to specific IP addresses, including 192.42.116[.]58, 192.42.116[.]105, and 146.70.139[.]154.
Data from KEVIntel shows that there have been 792 recorded exploitation attempts over a 41-day period, originating from 65 different IP addresses across 18 countries, including the United States, China, and Australia. The latest activity was registered on August 4, 2026, with five attempts documented on that day.
Recommended Actions for Organizations
In response to the ongoing threats, Federal Civilian Executive Branch agencies are urged to install necessary patches by August 10, 2026, as per Binding Operational Directive 26-04. Doing so will help secure their networks against this critical vulnerability.
As cyber threats continue to evolve, addressing vulnerabilities like CVE-2026-8037 swiftly is crucial for maintaining network security and protecting sensitive information from unauthorized access.
