Skip to main content
Cyber News & CTI Reports :: 2026-08-08 | Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts
Contact Page | Privacy Policy

2026-08-08 | Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

1. AI Summary

CISA adds critical command injection flaw CVE-2026-8037 in Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog due to active exploitation. The vulnerability allows unauthenticated remote code execution via improper input sanitization in the escape_quotes() function.

2. IOCs

IOC Type Value Description Relevant MITRE ATT&CK Techniques
Ipaddress
192.42.116.58
Observed source IP for exploitation attempts targeting CVE-2026-8037 on LoadMaster T1059|T1190
Ipaddress
192.42.116.105
Observed source IP for exploitation attempts targeting CVE-2026-8037 on LoadMaster T1059|T1190
Ipaddress
146.70.139.154
Observed source IP for exploitation attempts targeting CVE-2026-8037 on LoadMaster T1059|T1190
Malwarename Progress Kemp LoadMaster Vulnerable load balancer product targeted in active exploitation campaigns T1190
Vulnerability CVE-2026-8037 Critical command injection vulnerability in Progress Kemp LoadMaster API. T1190

3. MITRE ATT&CK

Code Title
T1190 Exploitation for Client Execution - Exploiting CVE-2026-8037 to inject commands into Kemp LoadMaster
T1071 Application Layer Protocol - Potential misuse of load balancer protocols
T1027 Obfuscated Files or Information - Obfuscated Files or Information - Improper input handling may enable evasion techniques
T1133 External Remote Services - Targeted exploitation of externally facing LoadMaster appliances
T1046 Network Service Discovery - Possible internal network scanning post-exploitation
T1059 Command and Scripting Interpreter - Use of injected system commands via the vulnerability
T1005 Data from Local System - Potential access to sensitive configuration or session data
T1082 System Information Discovery - Enumeration of system settings on compromised device
T1083 File and Directory Discovery - Possible traversal or manipulation of filesystem
T1070 Indicator Removal on Host - Possible cleanup actions post-exploitation

4. Targets

Type Value
Country Australia
Country China
Country Indonesia
Country Japan
Country Poland
Country United States
Sector Network Infrastructure / Load Balancing

5. Article Details

6. Original text

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. The vulnerability, tracked as

CVE-2026-8037
(CVSS score: 9.6), is a command injection flaw that could be weaponized to achieve arbitrary code execution on susceptible devices. "Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints," CISA said . In an analysis published in June 2026, watchTowr Labs described the issue as present in a function named "escape_quotes()" within the load balancer application and that it stemmed from improper handling of user-supplied input, ultimately enabling command injection. Successful exploitation of the flaw can allow an unauthenticated attacker to run arbitrary commands on the affected appliance without having to possess valid credentials. The addition comes a little over a month after eSentire said it's seeing active exploitation efforts targeting the flaw, although it noted those efforts were largely unsuccessful. The attacks originated from the following IP addresses, per the Canadian security vendor - 192.42.116[.]58 192.42.116[.]105 146.70.139[.]154 According to telemetry data captured by KEVIntel, a total of 792 exploitation attempts have been observed over the last 41 days from 65 unique IP addresses from 18 countries, including
Australia
,
China
,
Indonesia
,
Japan
,
Poland
, and the U.S. The last activity was recorded on August 4, 2026, when five exploitation attempts were detected.

In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies are recommended to apply the necessary patches by August 10, 2026, to secure their networks in accordance with Binding Operational Directive (BOD) 26-04.