CISA Urges Immediate Patching of Critical Progress LoadMaster Vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent directive for federal agencies to patch a critical vulnerability in Progress Kemp LoadMaster. The flaw, identified as CVE-2026-8037, allows unauthenticated remote attackers to execute arbitrary commands. This vulnerability, with a CVSS score of 9.6, poses a significant risk as LoadMaster appliances are often positioned at the network edge, providing visibility into critical internal services. The vulnerability was disclosed in June, and exploitation attempts began shortly after technical details were published. CISA has added the flaw to its Known Exploited Vulnerabilities catalog, requiring agencies to patch it within three days.