Threat actors are actively exploiting a critical Progress Kemp LoadMaster command injection vulnerability in wild attacks, prompting federal cybersecurity officials to issue an emergency remediation mandate. The flaw, tracked as CVE-2026-8037, allows unauthenticated remote attackers to execute arbitrary system commands on unpatched LoadMaster appliances. Because Application Delivery Controllers (ADCs) sit at the perimeter of corporate and government networks to distribute high-volume web traffic, a compromise at this layer provides attackers with direct, unauthenticated control over key network entry points.
Active Exploitation Triggers Urgent Directives
CISA added CVE-2026-8037 to its Known Exploited Vulnerabilities catalog after confirming active attack activity targeting exposed devices. Under Binding Operational Directive (BOD) 26-04, U.S. Federal Civilian Executive Branch (FCEB) agencies have been ordered to secure or patch their vulnerable LoadMaster servers within a strict three-day timeframe. While federal directives legally govern only executive agencies, commercial enterprises are advised to align with the same deadline given the severity of the flaw and the ease with which command injection attacks can be automated.
Data from threat monitoring non-profit Shadowserver shows that nearly 300 Kemp LoadMaster management interfaces remain publicly reachable over the internet. While a portion of these visible endpoints may represent active honeypots or instances that have already mitigated the flaw, any unpatched administrative port exposed to the internet represents an immediate attack vector.
Technical Mechanics and Blast Radius
At its technical core, CVE-2026-8037 is an unauthenticated command injection vulnerability located within unsanitized API input handlers across several command endpoints. When an API endpoint fails to validate or sanitize user-supplied input strings before passing them to the underlying system shell, an attacker can craft malicious HTTP requests containing shell metacharacters (such as semicolons, pipes, or subshell expansions) to execute arbitrary code.
In an Application Delivery Controller architecture, this security failure carries severe consequences. ADCs like Progress Kemp LoadMaster sit directly in front of application pools to manage traffic distribution, conduct health checks, and perform SSL/TLS decryption offloading. To fulfill these functions, the load balancer operates with elevated system-level privileges on the underlying OS.
Exploiting this command injection vulnerability gives an attacker remote code execution with root or administrative privileges on the perimeter appliance itself. From this position, the blast radius encompasses:
- Traffic Interception and Decryption: Because the load balancer terminates SSL/TLS connections, a compromised unit allows adversaries to intercept, log, or manipulate sensitive traffic—including cleartext credentials, API keys, and session tokens—before it reaches internal servers.
- Lateral Movement: The appliance acts as a trusted pivot point. Attackers can leverage the LoadMaster’s existing network routes and internal trust relationships to scan and exploit back-end application servers, databases, and microservices that sit behind the load balancer.
- Infrastructure Persistence: Threat actors can deploy webshells, alter load-balancing configurations to route user traffic to adversary-controlled servers, or disable security logging mechanisms entirely.
Affected Scope and Enterprise Impact
Progress Kemp LoadMaster is deployed across more than 100,000 installations globally, supporting high-profile enterprises and government agencies such as Amazon and the U.S. Air Force. Progress Software reports that 80% of Fortune 500 organizations utilize its technology portfolio.
The vulnerability impacts multiple software release branches of LoadMaster as well as integrated Web Application Firewall components:
- Kemp LoadMaster GA: Versions
v7.2.63.1and older. - Kemp LoadMaster LTSF (Long Term Support Feature): Versions
v7.2.54.17and older. - MOVEit WAF: All versions prior to
GA v7.2.63.2.
Although Progress released patches for this flaw in June, confirmation of active exploitation indicates that threat actors are successfully scanning for and targeting unpatched devices. This incident follows related security alerts across Progress Software’s product ecosystem, including recent notifications instructing ShareFile customers to shut down on-premises Storage Zone Controller servers due to an actively exploited high-severity path traversal zero-day flaw.
Immediate Remediation Steps
Organizations relying on Kemp LoadMaster or MOVEit WAF appliances should execute the following actions immediately:
- Apply Software Patches: Upgrade Kemp LoadMaster GA releases to version
v7.2.63.2or higher, and LTSF releases to versionv7.2.54.18or higher. Ensure MOVEit WAF deployments are updated to versionGA v7.2.63.2or later. - Restrict Management Access: Ensure that administrative interfaces and API command endpoints are not exposed to the public internet. Restrict access strictly to internal management VLANs or enforce zero-trust access controls (ZTNA) and strict IP allowlists.
- Audit Logged API Requests: Review web server and API access logs for anomalous HTTP requests targeting command endpoints that contain URL-encoded command injection syntax or unexpected process creation events under the LoadMaster web service context.
Related content
CISA Mandates Immediate Patch for Actively Exploited Progress LoadMaster RCE Flaw
AdvisoryProgress LoadMaster Critical Command Injection Advisory (CVE-2026-8037)
Security NewsUK ACRO Criminal Records Office Reprimanded After Unpatched CMS Led to Two-Year Breach
Security NewsAdobe Patches Maximum-Severity CVSS 10.0 Zero-Click Flaw in Campaign Classic
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call