CVE-2026-8037: the technical risk summarized
Tracked as CVE-2026-8037, the flaw is a command injection vulnerability that stems from unsanitized API inputs in multiple command endpoints. That combination allows unauthenticated actors to run arbitrary commands on affected Kemp LoadMaster devices. Progress released security updates in June to address the issue for affected builds: GA v7.2.63.1 or older and LTSF v7.2.54.17 or older. Progress also confirmed the bug affects all MOVEit WAF (Web Application Firewall) versions before GA v7.2.63.2.
Progress Kemp LoadMaster and MOVEit WAF: where the exposure matters
Kemp LoadMaster is an Application Delivery Controller (ADC) and server load balancer used to distribute incoming web traffic, optimize application performance, and maintain availability. Progress Software says 80% of Fortune 500 companies use its products and services, and that Kemp LoadMaster has over 100,000 deployments worldwide. The product is used by a mix of private-sector tech companies and government entities: Progress cited examples including Amazon and the U.S. Air Force.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleCISA action under Binding Operational Directive 26-04
On Friday, the U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-8037 to its catalog of actively exploited vulnerabilities. CISA ordered U.S. Federal Civilian Executive Branch (FCEB) agencies to secure their LoadMaster servers within three days, as required by Binding Operational Directive 26-04. The agency warned that, "This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise," and urged all defenders to prioritize patching CVE-2026-8037 to block incoming attacks.
Internet exposure and the unresolved tally
Internet threat watchdog Shadowserver reported that nearly 300 Kemp LoadMaster instances are exposed online. Shadowserver's count, however, comes with a key unknown: there is no information regarding how many of those nearly 300 are honeypots or have already been secured against CVE-2026-8037 attacks. That uncertainty leaves defenders without a clear public inventory of vulnerable, internet-facing appliances.
What this means for technologists, U.S. Federal Civilian Executive Branch agencies, and enterprises
- Technologists and security teams: Progress's June patches target specific older builds (GA v7.2.63.1 or older; LTSF v7.2.54.17 or older) and MOVEit WAF versions prior to GA v7.2.63.2 — teams must check versioning and apply vendor fixes. CISA's advisory and the addition to the catalog of actively exploited vulnerabilities make prioritization urgent.
- U.S. Federal Civilian Executive Branch agencies: BOD 26-04 imposes a three-day remediation requirement for FCEB agencies, creating a hard operational timeline to discover, patch, or otherwise mitigate exposed LoadMaster instances.
- Enterprises and customers using related Progress products: Progress previously emailed ShareFile customers using Storage Zone Controllers to immediately shut down servers after identifying a "credible external security threat" to on-premises ShareFile software. Days later, the company released patches for a high-severity ShareFile path traversal zero-day, while telling BleepingComputer that it had "no indication of unauthorized access to any ShareFile customer account or data, and we have not identified any active threat."
Two factual details sharpen the practical risk picture: Progress claims a very large installed base for Kemp LoadMaster, and Shadowserver reports nearly 300 internet-facing instances. Compounding that, the Picus whitepaper cited in the advisory material notes industry detection gaps — security teams log 54% of successful attacks and alert on just 14% — a reminder that exploitation can move through environments unseen unless detection and response controls are also evaluated.
Progress published patches in June; CISA has declared active exploitation and issued a three‑day remediation order for federal civilian agencies; Shadowserver reports nearly 300 exposed instances, but does not say how many are decoys or already patched. The central unanswered operational questions are therefore concrete: how many of the nearly 300 internet‑exposed LoadMaster appliances remain unpatched and reachable, and how quickly organizations subject to BOD 26‑04 — and those outside its scope — will apply the June fixes or take compensating controls.




