# CISA adds exploited Progress LoadMaster flaw to KEV catalog

_Monday, August 10, 2026 at 5:31 AM EDT · Security · Latest · Tier 1 — Major_

![CISA adds exploited Progress LoadMaster flaw to KEV catalog — Primary](https://www.securityweek.com/wp-content/uploads/2025/07/CISA-KEV.jpg)

CISA added CVE-2026-8037, a critical Progress Kemp LoadMaster vulnerability, to its Known Exploited Vulnerabilities catalog and told federal agencies to patch it within three days, SecurityWeek reported. The flaw is an unauthenticated OS command injection that can permit remote code execution, according to Progress' advisory. The report says exploitation began after technical details and proof-of-concept code were published in late June. Affected products also include ECS Connection Manager, Connection Manager for ObjectScale, and MOVEit WAF.

## Sources

- [SecurityWeek](https://www.securityweek.com/cisa-urges-immediate-patching-of-exploited-progress-loadmaster-vulnerability/)

---
Canonical: https://techandbusiness.org/newswire/w-O4exa-zvUkucZCpGTkeV
Retrieved: 2026-08-11T02:18:18.779Z
Publisher: Tech & Business (techandbusiness.org)
