CISA Warns of Critical Vulnerability in Progress Kemp LoadMaster, Urges Immediate Patching
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a critical vulnerability in the Progress Kemp LoadMaster, a widely used Application Delivery Controller. This vulnerability, identified as CVE-2026-8037, allows unauthenticated attackers to execute arbitrary commands on unpatched devices. Progress Software has released updates to address this issue, but CISA has added the flaw to its catalog of actively exploited vulnerabilities, mandating U.S. Federal Civilian Executive Branch agencies to secure their systems within three days. The vulnerability poses significant risks to federal enterprises and potentially other organizations using the affected software.