<entry_summary>CISA has warned of active exploitation of a critical command injection vulnerability (CVE-2026-8037) in Progress Kemp LoadMaster appliances. The flaw allows unauthenticated attackers to execute arbitrary commands via unsanitized API inputs. CISA has ordered U.S. Federal Civilian Executive Branch agencies to patch the vulnerability immediately to prevent unauthorized access.</entry_summary>
| IOC Type | Value | Description | Relevant MITRE ATT&CK Techniques |
|---|---|---|---|
| Vulnerability | CVE-2026-8037 | Critical command injection vulnerability in Progress Kemp LoadMaster API. | T1190 |
| Code | Title |
|---|---|
| T1190 | Exploit Public-Facing Application |
| T1059 | Command and Scripting Interpreter |
| Type | Value |
|---|---|
| Company | Amazon |
| Company | U.S. Air Force |
| Sector | Government |
| Sector | Technology |
| Sector | U.S. Federal Civilian Executive Branch (FCEB) agencies |
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity Progress Kemp LoadMaster command injection vulnerability. Kemp LoadMaster is a very popular Application Delivery Controller (ADC) and server load balancer used by tech companies and
Last month, Progress also emailed ShareFile customers who were using Storage Zone Controllers to immediately shut down servers after identifying what it described at the time as a "credible external security threat" targeting the on-premises secure file-sharing software. Days later, the company released security patches for a high-severity ShareFile path traversal zero-day vulnerability, but told BleepingComputer that it had "no indication of unauthorized access to any ShareFile customer account or data, and we have not identified any active threat." Test every layer before attackers do Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen. The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection. Get the whitepaper