CISA adds critical command injection flaw CVE-2026-8037 in Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog due to active exploitation. The vulnerability allows unauthenticated remote code execution via improper input sanitization in the escape_quotes() function.
| IOC Type | Value | Description | Relevant MITRE ATT&CK Techniques |
|---|---|---|---|
| Ipaddress |
192.42.116.58
|
Observed source IP for exploitation attempts targeting CVE-2026-8037 on LoadMaster | T1059|T1190 |
| Ipaddress |
192.42.116.105
|
Observed source IP for exploitation attempts targeting CVE-2026-8037 on LoadMaster | T1059|T1190 |
| Ipaddress |
146.70.139.154
|
Observed source IP for exploitation attempts targeting CVE-2026-8037 on LoadMaster | T1059|T1190 |
| Malwarename | Progress Kemp LoadMaster | Vulnerable load balancer product targeted in active exploitation campaigns | T1190 |
| Vulnerability | CVE-2026-8037 | Critical command injection vulnerability in Progress Kemp LoadMaster API. | T1190 |
| Code | Title |
|---|---|
| T1190 | Exploitation for Client Execution - Exploiting CVE-2026-8037 to inject commands into Kemp LoadMaster |
| T1071 | Application Layer Protocol - Potential misuse of load balancer protocols |
| T1027 | Obfuscated Files or Information - Obfuscated Files or Information - Improper input handling may enable evasion techniques |
| T1133 | External Remote Services - Targeted exploitation of externally facing LoadMaster appliances |
| T1046 | Network Service Discovery - Possible internal network scanning post-exploitation |
| T1059 | Command and Scripting Interpreter - Use of injected system commands via the vulnerability |
| T1005 | Data from Local System - Potential access to sensitive configuration or session data |
| T1082 | System Information Discovery - Enumeration of system settings on compromised device |
| T1083 | File and Directory Discovery - Possible traversal or manipulation of filesystem |
| T1070 | Indicator Removal on Host - Possible cleanup actions post-exploitation |
| Type | Value |
|---|---|
| Country | Australia |
| Country | China |
| Country | Indonesia |
| Country | Japan |
| Country | Poland |
| Country | United States |
| Sector | Network Infrastructure / Load Balancing |
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. The vulnerability, tracked as
In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies are recommended to apply the necessary patches by August 10, 2026, to secure their networks in accordance with Binding Operational Directive (BOD) 26-04.