Critical Progress LoadMaster flaw now actively exploited in attacks

Critical Progress LoadMaster flaw now actively exploited in attacks
CISA warned that attackers are actively exploiting CVE-2026-8037, a critical command injection flaw in Progress Kemp LoadMaster that can let unauthenticated threat actors run arbitrary commands on exposed appliances. Progress has already released patches, and CISA is urging all defenders to prioritize remediation, especially for the widely deployed LoadMaster and MOVEit WAF products. #CVE-2026-8037 #ProgressKempLoadMaster #ProgressSoftware #CISA #MOVEitWAF

Keypoints

  • CISA says CVE-2026-8037 is being actively exploited in the wild.
  • The flaw affects Progress Kemp LoadMaster and MOVEit WAF versions.
  • Unauthenticated attackers can execute arbitrary commands through unsanitized API inputs.
  • Progress released security updates for impacted LoadMaster and MOVEit WAF versions.
  • CISA ordered U.S. federal agencies to patch affected systems within three days.

Read More: https://www.bleepingcomputer.com/news/security/cisa-warns-of-critical-progress-loadmaster-flaw-exploited-in-attacks/