CISA Adds LoadMaster Flaw After 792 Exploit Attempts
The Hacker News covered CISA's KEV listing for CVE-2026-8037 after KEVIntel telemetry counted 792 exploitation attempts against Progress Kemp LoadMaster over 41 days.

The Hacker News covered CISA's decision to add CVE-2026-8037, a critical Progress Kemp LoadMaster command-injection flaw, to the Known Exploited Vulnerabilities catalog after public evidence of exploitation activity.
The flaw carries a CVSS score of 9.6 and affects Progress Kemp LoadMaster appliances.
CISA's catalog entry identifies the weakness as unauthenticated command execution through unsanitized input across multiple command endpoints, putting exposed appliances at risk without requiring valid credentials.
Exploitation Evidence Drives The KEV Listing
watchTowr Labs traced the problem in June 2026 to the LoadMaster application's escape_quotes() function and improper handling of user input.
The technical finding gave defenders a concrete code path for the command-injection issue before CISA moved the vulnerability into KEV.
eSentire had already observed exploitation efforts against the flaw a little over a month before the KEV addition, though those attempts were described as largely unsuccessful.
The Canadian security vendor linked the activity to three IP addresses, giving network teams indicators to compare against their own logs.
Telemetry Shows 41 Days Of Attempts
Telemetry data captured by KEVIntel, as cited by The Hacker News, counted 792 exploitation attempts over 41 days from 65 unique IP addresses in 18 countries, including Australia, China, Indonesia, Japan, Poland and the United States.
The latest activity in the dataset was recorded on August 4, 2026, when five attempts were detected.
Those figures make the case operational rather than theoretical: exploitation has been observed across multiple countries and weeks, while confirmed intrusions or victims were not identified.
The public evidence is still limited to attempts, IP indicators and vulnerability mechanics.
Federal Agencies Face An August 10 Deadline
In its August 7 alert, CISA set an August 10, 2026 patch deadline for Federal Civilian Executive Branch agencies under Binding Operational Directive 26-04.
The directive applies to federal civilian agencies, while CISA's separate guidance urges other organisations to prioritise remediation of KEV catalog vulnerabilities.
For operators beyond FCEB agencies, the practical test is whether exposed LoadMaster systems are updated before the same exploit traffic reaches them.




















