CISA: Patch Exploited Progress LoadMaster Flaw Now
CISA urged federal agencies to immediately patch CVE-2026-8037, an unauthenticated Progress Kemp LoadMaster OS command injection exploited in the wild that allows remote root code execution.
The Cybersecurity and Infrastructure Security Agency directed federal agencies to apply fixes for CVE-2026-8037, a critical unauthenticated OS command injection in Progress Kemp LoadMaster that has been observed exploited in the wild. The vulnerability carries a CVSS score of 9.6 and was added to CISA’s Known Exploited Vulnerabilities catalog with a three-day remediation deadline. Progress disclosed the defect on June 4.
The flaw affects LoadMaster appliances and related products, including ECS Connection Manager, Connection Manager for ObjectScale and MOVEit WAF. Vendor advisories identify affected LoadMaster GA releases up to 7.2.63.1 and LTSF releases up to 7.2.54.17.
Technical analysis traces the bug to handling of the apiuser parameter on the accessv2 endpoint. A Zero Day Initiative advisory states: “The specific flaw exists within the handling of the apiuser parameter provided to the accessv2 endpoint. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of root.” Researchers found that an escape_quotes() function allocates an uninitialized heap buffer and does not append a null terminator after escaping input. That omission can permit out-of-bounds reads of adjacent memory and enable command execution via a subsequent system() call.
Public proof-of-concept code and technical analysis were published at the end of June. Security firms reported exploitation attempts began shortly afterward, with some initial attempts not immediately achieving full compromise. A cybersecurity firm warned: “Because LoadMaster appliances are frequently positioned at the network edge and often have visibility into critical internal services, compromise of the device could facilitate initial access and further malicious activity within the environment.”
CISA’s KEV listing shortens the remediation window for federal entities and requires agencies to prioritize updates. Progress and industry analysts advise administrators to verify product versions and install vendor updates or apply provided mitigations. Network operators are advised to monitor edge appliances for indicators of compromise and to review access logs for unusual activity. If an affected appliance is reachable from external networks, organizations should treat the device as exposed to elevated risk.








