CISA Warns of Critical Progress LoadMaster Flaw Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity Progress Kemp LoadMaster command injection vulnerability. Kemp LoadMaster is a popular Application Delivery Controller (ADC) and server load balancer us…
Intelligence analysis by Llama

CISA warned that hackers are exploiting a critical-severity Progress Kemp LoadMaster command injection vulnerability, which enables unauthenticated attackers to execute arbitrary commands on unpatched LoadMaster appliances. The vulnerability affects all MOVEit WAF versions before GA v7.2.63.2 and has been exploited in nearly 300 Kemp LoadMaster instances exposed online.
Imagine you have a super-powerful tool that helps your website handle lots of visitors. But, if someone finds a way to trick the tool, they can do bad things to your website. That's what's happening with the Progress Kemp LoadMaster tool. Hackers are finding ways to trick it, and that's why the government is warning people to fix the problem.
Analysis
CISA Warning and CVE-2026-8037 Vulnerability Description
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity Progress Kemp LoadMaster command injection vulnerability. Tracked as CVE-2026-8037, this vulnerability enables unauthenticated attackers to execute arbitrary commands on unpatched LoadMaster appliances by exploiting unsanitized API inputs in multiple command endpoints. The vulnerability affects all MOVEit WAF versions before GA v7.2.63.2.
Impact and Exploitation
According to Internet threat watchdog Shadowserver, nearly 300 Kemp LoadMaster instances are exposed online. However, there is no information regarding how many of them are honeypots or have already been secured against CVE-2026-8037 attacks. On Friday, CISA added the flaw to its catalog of actively exploited vulnerabilities, ordering U.S. Federal Civilian Executive Branch (FCEB) agencies to secure their servers within three days as mandated by Binding Operational Directive 26-04.
Progress Software Response and Patching
Progress Software released security updates to patch the vulnerability in Kemp LoadMaster (GA v7.2.63.1 or older and LTSF v7.2.54.17 or older) and also confirmed that it impacts all MOVEit WAF versions before GA v7.2.63.2. The company emailed ShareFile customers who were using Storage Zone Controllers to immediately shut down servers after identifying what it described at the time as a 'credible external security threat' targeting the on-premises secure file-sharing software. Days later, the company released security patches for a high-severity ShareFile path traversal zero-day vulnerability, but told BleepingComputer that it had 'no indication of unauthorized access to any ShareFile customer account or data, and we have not identified any active threat.'
Key points
- CISA warned that hackers are exploiting a critical-severity Progress Kemp LoadMaster command injection vulnerability.
- The vulnerability affects all MOVEit WAF versions before GA v7.2.63.2.
- Nearly 300 Kemp LoadMaster instances are exposed online.
- Progress Software released security updates to patch the vulnerability in Kemp LoadMaster.
- The company emailed ShareFile customers to immediately shut down servers after identifying a 'credible external security threat'.
If the vulnerability is patched quickly, the number of attacks will decrease, and the risk of data breaches will be reduced. This will also give organizations more time to prepare and respond to potential threats.
If the vulnerability is not patched quickly, the number of attacks will increase, and the risk of data breaches will be higher. This could lead to significant financial losses and damage to an organization's reputation.


