Vulnerability Management, Patch/Configuration Management

Progress LoadMaster bug added to CISA list of exploited vulnerabilities

Binary code on screen with red glowing "BUG" text, symbolizing software malfunction, coding error, or system glitch. Ideal for tech content, debugging, and cybersecurity topics.

The Cybersecurity and Infrastructure Security Agency (CISA) added a critical bug to its known exploited vulnerabilities (KEV) catalog that was actively exploiting Progress LoadMaster load balancers.

There are more than 100,000 deployments of the Progress LoadMaster load balancers across 80% of the Fortune 500.

Companies use the devices to ensure high availability and performance, and to protect apps across cloud, virtual, and hardware environments.

The CVSS 9.6 bug – CVE-2026-8037 – operates as a command injection flaw that lets an unauthenticated attacker execute arbitrary commands on a LoadMaster device by exploiting unsanitized input in multiple command endpoints.

Denis Calderone, chief technology officer at Suzu Labs, explained that load balancers are a particularly dangerous target because they sit directly in front of an organization's public-facing applications. Calderone said they often terminate transport layer security (TLS), hold private keys or service credentials, and maintain trusted connections into internal application pools.

Calderone said an unauthenticated attacker who takes control of one has a path from the internet edge to systems the organization already trusts. That’s why CVE-2026-8037 demands more than applying firmware.

“Administrators need a full compromise review and an architecture that limits administrative interfaces to a VPN, jump host, or explicit network allowlist,” said Calderone.

Adrian Culley, offensive security engineer at SafeBreach, said CVE-2026-8037 follows a pattern we now see almost monthly: a critical, unauthenticated command injection in an internet-facing appliance, a vendor patch by Progress available since June, and active exploitation two months later.

“CISA's decision to add it to the KEV catalog on Aug. 7, with a three-day remediation deadline under BOD 26-04, tells us how seriously it’s being treated,” said Culley.

With more than 100,000 devices deployed, Culley said the issue is not that organizations don't know about the fix, it’s that they cannot answer the harder question quickly enough: Is this appliance actually exposed in my environment, and would my controls detect an attacker who reached it?

“Patch availability is not the same as patch coverage, and asset inventories are rarely as accurate as we would like,” said Culley. “Load balancers and WAFs sit in the trust boundary — precisely where blind spots are most expensive.”

Erick Downs, regional president at Courser, added that security teams should immediately verify they are running the patched LoadMaster versions, review appliance logs and authentication activity for signs of unexpected API access or command execution (using AI to maximize efficiency here), and perform a thorough forensic review of any internet-facing instances to determine whether compromise occurred before remediation.

“Based on CISA's warning that the vulnerability is being actively exploited, teams should reduce exposure by restricting management interfaces, limiting public access wherever possible, strengthening monitoring and detection around these systems, and accelerating vulnerability management processes for critical edge infrastructure,” said Downs.

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds