Our automated tracking framework flagged that CISA added CVE-2026-8037 (Progress LoadMaster) to the Known Exploited Vulnerabilities (KEV) catalog on August 10, 2026. A KEV listing is CISA’s official confirmation that the flaw is being exploited in the wild — U.S. federal agencies must patch it by a fixed deadline. Here is what our data shows.
What CISA Reported
CISA describes the flaw as follows: “Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.”
Under Binding Operational Directive rules, U.S. federal agencies must remediate CVE-2026-8037 by August 10, 2026 — a 3-day window. Private organizations are not bound by the deadline, but CISA treats it as the benchmark for how urgently a confirmed-exploited flaw should be patched.
The Details
| CVE | CVE-2026-8037 |
| Vendor / product | Progress LoadMaster |
| Vulnerability | Progress LoadMaster Command Injection Vulnerability |
| CVSS base score | 9.6 |
| Added to KEV | August 7, 2026 |
| Days public before listing (NVD → KEV lag) | 64 |
| Federal patch deadline | August 10, 2026 |
| Known ransomware use | No |
How This Compares to Progress’s Track Record
This one was public for 64 days before CISA confirmed exploitation — longer than Progress’s 64-day median, a vulnerability that sat exploitable in the open.
| Progress in the CISA KEV catalog | Value |
|---|---|
| Tracked KEV entries | 9 |
| Median lag (public → KEV listing) | 64 days |
| 0-day rate (exploited at or before disclosure) | 11% |
| Entries tied to known ransomware campaigns | 4 |
For perspective, the median across all 1662 tracked KEV entries is 271 days — Progress’s exploited vulnerabilities are flagged faster than the catalog average.
Other Recent Progress KEV Additions
The most recent Progress vulnerabilities CISA has confirmed as actively exploited, from our tracker:
| CVE | Product | Added to KEV | Lag (days) | Ransomware |
|---|---|---|---|---|
| CVE-2024-4885 | WhatsUp Gold | March 3, 2025 | 251 | No |
| CVE-2024-1212 | Kemp LoadMaster | November 18, 2024 | 271 | No |
| CVE-2024-6670 | WhatsUp Gold | September 16, 2024 | 18 | ⚠️ Yes |
| CVE-2024-4358 | Telerik Report Server | June 13, 2024 | 15 | No |
| CVE-2023-40044 | WS_FTP Server | October 5, 2023 | 8 | ⚠️ Yes |
What This Means for Defenders
CISA has added CVE-2026-8037, a command injection vulnerability in Progress LoadMaster, to its Known Exploited Vulnerabilities (KEV) catalog. It’s a severe risk with a CVSS base score of 9.6, requiring urgent attention from security teams. Federal agencies must patch by August 10, 2026, just three days after its KEV listing on August 7, 2026. Organizations using Progress LoadMaster should prioritize patching to prevent active exploitation; KEV entries mean proven real-world attacks.
This vulnerability was public for 64 days before its KEV addition. This implies exploitation may have started shortly after disclosure, meaning a significant detection window for this vulnerability might’ve passed. All organizations running Progress LoadMaster are exposed and should immediately apply available patches. If patching isn’t possible before the August 10 deadline, restrict access to affected systems, use strict network segmentation, and increase monitoring for suspicious activity.
Related Coverage
- Critical Microsoft SharePoint Flaw CVE-2026-50522 (CVSS 9.8) Added to CISA KEV (July 2026)
- WordPress’s CVE-2026-63030 Was Exploited in 4 Days — Well Under Its 420-Day Median (July 2026)
How We Track This
This report was generated from our CISA KEV Lag Tracker, which syncs the official CISA KEV catalog daily and records the date each CVE is added. For every entry we retrieve the original NVD publication date and compute the lag in calendar days. No dates or figures on this page are estimated or taken from third-party sources — they come directly from CISA and NVD records.