On August 7, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-8037 to its Known Exploited Vulnerabilities (KEV) catalog after determining that attackers were exploiting the flaw in the wild.
What happened
The vulnerability affects Progress Kemp LoadMaster, an application delivery controller and load balancer. CISA said the command injection flaw allows an unauthenticated attacker to execute arbitrary commands on a LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.
The vulnerability has a Common Vulnerability Scoring System (CVSS) score of 9.6. CISA instructed federal civilian agencies to apply the vendor’s mitigations by August 10, 2026, or to discontinue use if the mitigations were unavailable. Progress originally disclosed the vulnerability on June 4 and released fixes in LoadMaster GA version 7.2.63.2 and LTSF version 7.2.54.18. According to Progress, the update corrected a remote code execution vulnerability affecting the cipher-set user interface and API command.
In the know
Progress Kemp LoadMaster is a family of application delivery controllers (ADCs) and load balancers that manages and distributes incoming traffic across multiple application servers. This prevents individual servers from becoming overloaded and helps organizations maintain application availability, performance, and scalability. LoadMaster can be deployed as hardware, virtual, cloud-native, or bare-metal software and includes capabilities such as server health checking, SSL/TLS acceleration and offloading, content-based traffic routing, and high-availability configurations.
Certain subscriptions also include a web application firewall (WAF), which inspects web traffic and helps block application-layer attacks before they reach backend servers. LoadMaster sits between users and an organization’s applications, directing each request to an appropriate healthy server while applying configured performance and security controls.
Going deeper
Agencies were directed to apply Progress’s mitigations, follow CISA’s forensic-triage requirements, evaluate each asset’s internet exposure, and discontinue affected products when effective mitigations were unavailable, in accordance with Binding Operational Directive 26-04. Although the mandate applies specifically to federal agencies, it provides a clear remediation benchmark for healthcare organizations using LoadMaster.
In this case the benchmark could include:
- How quickly the vulnerability should be addressed
- Which vendor-recommended fixes or mitigations should be applied
- When affected systems should be taken out of service if they cannot be secured
- How urgently organizations should prioritize the vulnerability.
Why it matters
For healthcare organizations, a compromised LoadMaster could disrupt access to patient portals, telehealth platforms, scheduling tools, billing systems, or clinical applications placed behind the appliance. Attackers could potentially intercept traffic, steal credentials, redirect users, disrupt availability, or use the device as an entry point into systems containing electronic protected health information. These outcomes have not been publicly attributed to CVE-2026-8037, but they represent credible risks given the appliance’s privileged network position.
The vulnerability also reflects a recurring security concern. CVE-2024-1212 was another unauthenticated command-injection vulnerability in LoadMaster that CISA confirmed was being exploited. CVE-2024-7591 involved a similar command-injection weakness, although Progress reported no known exploitation at the time. Separately, the 2023 MOVEit campaign demonstrated how the exploitation of another widely deployed Progress product could lead to extensive downstream exposure. MOVEit is a different product and vulnerability, but the incident shows why healthcare entities must quickly inventory, patch, and investigate exposed infrastructure.
See also: HIPAA Compliant Email: The Definitive Guide (2026 Update)
FAQs
Does a KEV listing confirm that every vulnerable organization has been compromised?
Inclusion confirms that attackers have exploited the vulnerability against one or more real life targets. It does not establish that every organization using the affected product was breached or identify the victims.
Is a KEV vulnerability always rated critical?
The catalog is based on observed exploitation rather than only a vulnerability’s CVSS severity score. Attackers may exploit a medium or high-severity vulnerability when it provides useful access or is widely exposed.
Are CISA remediation deadlines mandatory for healthcare organizations?
CISA’s binding directives apply to Federal Civilian Executive Branch agencies. They do not automatically impose the same deadlines on private healthcare organizations.
What is the CVSS score?
It measures severity, not whether attackers are actively exploiting the flaw or the precise risk to a particular organization. Therefore, CVE-2026-8037’s 9.6 score means it can have critical technical consequences.
