Enterprise IT Support β€’ Bangkok & Nationwide

Technology newsroom

CISA Issues Urgent Alert: Critical Vulnerability in Kemp LoadMaster Exploited Over 792 Times, Admins Must Update Immediately

CISA has added the critical vulnerability CVE-2026-8037 in Progress Kemp LoadMaster to its KEV list after detecting over 792 widespread exploitation attempts. System administrators are advised to apply the patch immediately.

Edited by SyncTech Solution Published Source Original source
CISA Issues Urgent Alert: Critical Vulnerability in Kemp LoadMaster Exploited Over 792 Times, Admins Must Update Immediately

πŸ“Œ Key Highlights:
- CISA has added CVE-2026-8037, a Critical (9.6) vulnerability in Progress Kemp LoadMaster, to its KEV list, confirming active exploitation.
- The Command Injection vulnerability allows malicious actors to remotely execute arbitrary code on the device without authentication.
- At least 792 attempts to exploit this vulnerability have been reported, making it a threat that requires the most urgent attention.

🚨 CISA, the U.S. Cybersecurity and Infrastructure Security Agency, has officially announced the addition of a critical vulnerability in the popular Load Balancer device, Progress Kemp LoadMaster, to its Known Exploited Vulnerabilities (KEV) catalog. This action follows clear reports and evidence that the vulnerability has been widely exploited by hackers.

βš™οΈ The vulnerability is tracked under CVE-2026-8037 and has received a high severity score of 9.6 out of 10 according to CVSS standards. It is a Command Injection vulnerability that allows remote attackers to directly send and execute malicious commands on the LoadMaster system. This could lead to full system control, data theft, or its use as a springboard for further attacks on other systems within the network.

πŸ›‘οΈ Of particular concern is the detection of over 792 attempts to exploit this vulnerability, indicating that hackers are actively scanning for unpatched devices. CISA has therefore issued a directive requiring U.S. federal agencies to urgently apply patches to close this vulnerability and recommends that all private sector organizations using these devices immediately update to prevent potential damage.

πŸ’¬ What Load Balancer brands does your organization use, and what is your plan for addressing urgent vulnerabilities like this?

Let’s build what’s next

Better IT starts with understanding your business.

Tell our engineers what you need and receive an initial recommendation at no cost.