Back to advisories

CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability

Progress Kemp LoadMaster has a critical RCE vulnerability (CVE-2026-8037) that allows unauthenticated attackers to execute arbitrary commands. Active exploitation started around June 29. Any organization running affected LoadMaster versions needs to patch immediately or risk full appliance compromise and lateral movement into the network.

CRITICALAdvisoryAug 10, 2026
Action required
Identify all Progress Kemp LoadMaster instances in your environment and patch to the latest patched version immediately. If patching cannot be done today, isolate the appliance or block external access until patched.
Affected products
Kemp LoadMasterProgressECS Connection ManagerConnection Manager for ObjectScaleMOVEit WAF