The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity Progress Kemp LoadMaster command injection vulnerability.

CISA adds Progress Kemp LoadMaster CVE-2026-8037 to KEV after active exploitation reports, with 792 attempts logged across 65 IPs in 41 days.

CISA urges federal agencies to immediately patch CVE-2026-8037, an exploited remote code execution flaw in Progress LoadMaster.