CISA Adds Critical Progress LoadMaster Command Injection to KEV Catalog

CISA has added CVE-2026-8037, a critical Progress LoadMaster command injection vulnerability actively exploited in the wild, to its Known Exploited Vulnerabilities Catalog, requiring prioritized remediation by federal agencies under BOD 26-04.

Why it matters

This vulnerability grants attackers full control over affected systems, posing a severe security risk that necessitates prompt operational attention.

SOC impact

Defenders must identify all instances of affected Progress LoadMaster assets and monitor for exploitation indicators related to CVE-2026-8037. Emphasize telemetry review and incident response readiness, especially within environments subject to BOD 26-04 requirements.

Recommended actions

  1. Identify and inventory all deployed Progress LoadMaster instances
  2. Review network telemetry for signs of command injection activity
  3. Assess compliance with BOD 26-04 remediation mandates
  4. Monitor relevant logs for anomalous command execution attempts
  5. Consult the CISA Known Exploited Vulnerabilities Catalog for updates

Executive Summary

The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-8037, a critical command injection vulnerability in Progress LoadMaster, to its Known Exploited Vulnerabilities Catalog. This vulnerability is actively leveraged by attackers, enabling total control over impacted systems. As detailed in BOD 26-04, federal agencies must prioritize remediation efforts. Beyond federal mandates, all organizations utilizing Progress LoadMaster should adopt risk-based vulnerability management practices and closely monitor their environments for exploitation attempts to reduce operational risk.

SOC Impact

Defenders must identify all instances of affected Progress LoadMaster assets and monitor for exploitation indicators related to CVE-2026-8037. Emphasize telemetry review and incident response readiness, especially within environments subject to BOD 26-04 requirements.

Authentication and Access Validation

  • Identify and inventory all deployed Progress LoadMaster instances
  • Review network telemetry for signs of command injection activity
  • Assess compliance with BOD 26-04 remediation mandates
  • Monitor relevant logs for anomalous command execution attempts
  • Consult the CISA Known Exploited Vulnerabilities Catalog for updates

Why It Matters

This vulnerability grants attackers full control over affected systems, posing a severe security risk that necessitates prompt operational attention.

Source