Contacts
Book a Meet
Close

Contacts

Bulgaria, Kavarna
Saudi Arabia, Riyadh

+359 875 328030

sales@diamatix.com

Contacts

Bulgaria, Kavarna
Saudi Arabia, Riyadh

+359 875 328030

sales@diamatix.com

112447

LoadMaster Vulnerability Enters CISA KEV: Edge Devices Need Verification, Not Only Patching

What Is Confirmed

CISA added CVE-2026-8037 to the Known Exploited Vulnerabilities (KEV) catalog following evidence of active exploitation. The vulnerability affects Progress Kemp LoadMaster, an application delivery and load balancing appliance often placed between the internet and internal services.

CVE-2026-8037 is a critical command injection vulnerability. Under specific conditions, it allows an unauthenticated remote attacker to execute commands on the LoadMaster appliance.

Progress published fixes on 4 June 2026. Affected versions include LoadMaster GA 7.2.63.1 and earlier, and LoadMaster LTSF 7.2.54.17 and earlier. Fixed versions are GA 7.2.63.2 and LTSF 7.2.54.18.

Why This Is Not a Routine Patch Alert

LoadMaster is not a standard internal application. These appliances often manage inbound traffic to critical services, terminate TLS connections, route requests and may have visibility into internal systems.

A compromise of an edge device can therefore matter beyond the vulnerability itself. An attacker may use the device’s position for initial access, traffic observation, configuration changes or movement toward internal services.

Patching is urgent here, but it is not enough as the only measure. After active exploitation, teams need to check whether the appliance was already touched.

The Technical Signal

According to watchTowr’s analysis, the vulnerability is linked to improper handling of input in the escape_quotes() function. Under certain conditions, this can allow command injection and command execution through system().

eSentire reported exploitation attempts from 29 June 2026. In the cases they analyzed, attempts were not successful, but the availability of public technical analysis and proof-of-concept code increases the likelihood of scanning and testing against exposed systems.

What Organizations Should Check

Organizations using Progress Kemp LoadMaster or related Progress ADC products should begin with inventory and exposure.

Practical checks:

  • whether affected LoadMaster versions are in use;
  • whether API access is enabled and from where it is reachable;
  • whether management or API interfaces are exposed to the internet;
  • whether fixes 7.2.63.2 or 7.2.54.18 have been applied;
  • whether unusual API requests to /accessv2 appear in logs;
  • whether new accounts, configuration changes or unexpected commands exist;
  • whether logs, network traffic and administrative actions have been reviewed;
  • whether compromise assessment was performed before and after updating.

The key question is not only whether the patch was installed. It is whether there is evidence that the appliance was used before remediation.

DIAMATIX Comment

From the DIAMATIX perspective, this case shows why edge infrastructure should be monitored as a critical layer, not treated as a separate network box.

Load balancers, reverse proxies, WAF (Web Application Firewall) and other edge devices often hold a privileged position. They receive external traffic, route it to internal services and store configurations that matter for application availability and security.

SOC (Security Operations Center) and MDR (Managed Detection and Response) processes should connect vulnerabilities, exposure, logs and network behavior. This helps teams distinguish “vulnerable but not exploited” from “vulnerable and likely used.”

Questions for CISO and IT Teams

  • Which edge devices are reachable from the internet?
  • Which of them expose management or API interfaces?
  • How are vulnerabilities already listed in CISA KEV prioritized?
  • Is there a compromise assessment process after patching?
  • Can we trace administrative activity retrospectively?
  • What is the recovery path if an edge appliance is compromised?

The practical takeaway: when an actively exploited vulnerability affects an edge device, the organization needs to patch quickly and verify whether access already occurred.

Check whether your edge infrastructure is only updated — or actually verified

DIAMATIX can help review exposure, logs, configurations and compromise indicators across LoadMaster, WAF, reverse proxy and other edge network devices.

Request an edge infrastructure and response readiness review with DIAMATIX.
Trusted · Innovative · Vigilant


Sources

  • Progress. LoadMaster 7.2.63.2 Release Notes — Fix for CVE-2026-8037.
  • Progress. LoadMaster 7.2.54.18 Release Notes — Fix for CVE-2026-8037.
  • NVD. CVE-2026-8037.
  • watchTowr Labs. Enterprise Tech In, Shell Out — Progress Kemp LoadMaster CVE-2026-8037.
  • eSentire. Progress Kemp LoadMaster Vulnerability Targeted.
  • SecurityWeek. CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability.

This article is based on publicly available information as of 11.08.2026.

Subscribe for latest updates & insights

Please enable JavaScript in your browser to complete this form.