The U.S. Cybersecurity and Infrastructure Security Agency (CISA) said that a critical-severity vulnerability in Progress Kemp LoadMaster is being actively exploited.

This security flaw allows threat actors to achieve remote code execution, which could lead to the full compromise of affected systems. Because the vulnerability is actively being used in the wild, immediate patching is required to prevent unauthorized network access.

The vulnerability is identified as CVE-2026-8037 [1]. It is a command-injection flaw that CISA has added to its Known Exploited Vulnerabilities (KEV) catalog. The agency's decision to list the flaw follows evidence that attackers are targeting the software to gain control over infrastructure.

Data indicates the scale of the threat is significant. Reports show that 792 exploit attempts were observed [2]. These attacks were carried out by 65 distinct IP addresses [3] over a period of 41 days [4].

CISA said that the risk of compromise is high for organizations using the affected Progress Kemp LoadMaster appliances. The agency said administrators should apply the necessary security updates immediately to mitigate the risk of remote code execution. The KEV catalog serves as a primary directive for federal agencies to prioritize patching to protect national security, and critical infrastructure.

792 exploit attempts were observed over a period of 41 days.

The addition of CVE-2026-8037 to the KEV catalog signals that the vulnerability is no longer a theoretical risk but a proven tool for attackers. The use of 65 different IP addresses suggests a coordinated effort or a widely distributed exploit kit, increasing the likelihood that a broad range of organizations are currently targeted.