Our automated tracking framework flagged that CISA added CVE-2026-8037 (Progress LoadMaster) to the Known Exploited Vulnerabilities (KEV) catalog on August 10, 2026. A KEV listing is CISA’s official confirmation that the flaw is being exploited in the wild — U.S. federal agencies must patch it by a fixed deadline. Here is what our data shows.

What CISA Reported

CISA describes the flaw as follows: “Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.”

Under Binding Operational Directive rules, U.S. federal agencies must remediate CVE-2026-8037 by August 10, 2026 — a 3-day window. Private organizations are not bound by the deadline, but CISA treats it as the benchmark for how urgently a confirmed-exploited flaw should be patched.

The Details

CVE CVE-2026-8037
Vendor / product Progress LoadMaster
Vulnerability Progress LoadMaster Command Injection Vulnerability
CVSS base score 9.6
Added to KEV August 7, 2026
Days public before listing (NVD → KEV lag) 64
Federal patch deadline August 10, 2026
Known ransomware use No

How This Compares to Progress’s Track Record

This one was public for 64 days before CISA confirmed exploitation — longer than Progress’s 64-day median, a vulnerability that sat exploitable in the open.

Progress in the CISA KEV catalog Value
Tracked KEV entries 9
Median lag (public → KEV listing) 64 days
0-day rate (exploited at or before disclosure) 11%
Entries tied to known ransomware campaigns 4

For perspective, the median across all 1662 tracked KEV entries is 271 days — Progress’s exploited vulnerabilities are flagged faster than the catalog average.

Other Recent Progress KEV Additions

The most recent Progress vulnerabilities CISA has confirmed as actively exploited, from our tracker:

CVE Product Added to KEV Lag (days) Ransomware
CVE-2024-4885 WhatsUp Gold March 3, 2025 251 No
CVE-2024-1212 Kemp LoadMaster November 18, 2024 271 No
CVE-2024-6670 WhatsUp Gold September 16, 2024 18 ⚠️ Yes
CVE-2024-4358 Telerik Report Server June 13, 2024 15 No
CVE-2023-40044 WS_FTP Server October 5, 2023 8 ⚠️ Yes

What This Means for Defenders

CISA has added CVE-2026-8037, a command injection vulnerability in Progress LoadMaster, to its Known Exploited Vulnerabilities (KEV) catalog. It’s a severe risk with a CVSS base score of 9.6, requiring urgent attention from security teams. Federal agencies must patch by August 10, 2026, just three days after its KEV listing on August 7, 2026. Organizations using Progress LoadMaster should prioritize patching to prevent active exploitation; KEV entries mean proven real-world attacks.

This vulnerability was public for 64 days before its KEV addition. This implies exploitation may have started shortly after disclosure, meaning a significant detection window for this vulnerability might’ve passed. All organizations running Progress LoadMaster are exposed and should immediately apply available patches. If patching isn’t possible before the August 10 deadline, restrict access to affected systems, use strict network segmentation, and increase monitoring for suspicious activity.

Related Coverage

How We Track This

This report was generated from our CISA KEV Lag Tracker, which syncs the official CISA KEV catalog daily and records the date each CVE is added. For every entry we retrieve the original NVD publication date and compute the lag in calendar days. No dates or figures on this page are estimated or taken from third-party sources — they come directly from CISA and NVD records.