792 exploitation attempts have been observed against a single critical flaw in Progress Kemp LoadMaster over a 41-day window, data show — a surge that prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add the bug to its Known Exploited Vulnerabilities catalog.
CISA adds CVE-2026-8037 to the KEV catalog
On Friday, CISA added CVE-2026-8037 — a command injection vulnerability with a CVSS score of 9.6 — to its Known Exploited Vulnerabilities (KEV) list after reports of active exploitation. "Progress LoadMaster contains a command injection vulnerability that allows an un‑authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints," CISA said.
How the flaw works: escape_quotes() and unsanitized input
Security researchers from watchTowr Labs, in an analysis published in June 2026, identified the problem in a function named "escape_quotes()" inside the load balancer application. The vendor-agnostic description from watchTowr Labs states the root cause as improper handling of user‑supplied input that can enable command injection. Because exploitation does not require valid credentials, a successful attack can allow an unauthenticated actor to run arbitrary commands on affected appliances.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageTelemetry and observed exploitation: KEVIntel and eSentire
Telemetry compiled by KEVIntel shows 792 exploitation attempts over the last 41 days originating from 65 unique IP addresses across 18 countries, including Australia, China, Indonesia, Japan, Poland, and the U.S. The most recent activity recorded in that feed was on August 4, 2026, when five exploitation attempts were detected.
Separately, Canadian security vendor eSentire reported seeing active exploitation efforts targeting the flaw a little over a month earlier, although it characterized those attempts as largely unsuccessful. eSentire attributed the attacks it tracked to three IP addresses: 192.42.116[.]58, 192.42.116[.]105 and 146.70.139[.]154.
Federal Civilian Executive Branch: BOD 26-04 and an August 10 deadline
With active exploitation observed in the wild, CISA recommended that Federal Civilian Executive Branch (FCEB) agencies apply the necessary patches by August 10, 2026, in accordance with Binding Operational Directive (BOD) 26-04. The directive establishes the patching expectation and sets the remediation date federal civilian agencies are to meet to secure their networks against CVE-2026-8037.
What this means for security teams, FCEB agencies, and LoadMaster operators
- Security teams: The vulnerability is an unauthenticated command injection tied to unsanitized input in multiple command endpoints and the escape_quotes() function; teams should prioritize patching and monitoring for suspicious command execution attempts on LoadMaster appliances.
- FCEB agencies: The BOD 26-04 remediation date of August 10, 2026 is the explicit benchmark for applying patches to affected systems to meet federal operational requirements.
- LoadMaster operators and enterprise IT: Telemetry shows hundreds of attempts from dozens of IP addresses across 18 countries, and some vendor-focused scanning and exploitation activity was reported; operators should apply vendor updates and review logs for the types of unauthenticated requests that CISA and researchers have flagged.
The sequence is straightforward: researchers identified a flaw tied to an input‑handling function; attackers tracked by security vendors and telemetry attempted exploitation in the wild; and CISA, citing active exploitation, placed the vulnerability on its KEV list and set a firm remediation timeline for federal civilian agencies. Whether additional exploitation will be recorded after the last noted activity on August 4, 2026 — and how rapidly nonfederal operators will apply vendor fixes ahead of the federal deadline on August 10 — will determine how acute this exposure becomes over the coming days.




