Attackers are exploiting a critical flaw in Progress LoadMaster, the load balancing appliance that sits in front of web applications at thousands of organizations. CISA added it to the government's list of vulnerabilities under active attack on 7 August, roughly two months after a fix became available.
The bug is CVE-2026-8037. According to CISA's alert, the addition is based on evidence of exploitation in the wild. CISA does not name the attackers, the victims or the timeframe, which is standard for these listings.
What is affected
The vulnerability is an operating system command injection in the API of Progress ADC products. The published entry describes an unauthenticated attacker being able to run arbitrary commands on the LoadMaster appliance by abusing unsanitized input across multiple command endpoints. It is scored 9.6 out of 10, which is critical.
Beyond that, the public record is thin. Progress' own advisory carries the affected version list and the upgrade path, and administrators should work from it rather than from the catalog entry. We covered the flaw when it was first disclosed in June, when it was described as letting hackers run code without a login.
Why this one matters
Two things make this worth moving on today. The first is placement: a load balancer is deliberately reachable from the internet and sees traffic for every application behind it, so an appliance that can be commanded without a login is an unusually good foothold.
The second is that the forecasting data had flagged it well before CISA did. Its EPSS score, which estimates the probability of exploitation activity within the next 30 days, sits at roughly 0.85, near the top of the range. Prediction is not proof, and plenty of high scoring CVEs are never touched, but in this case the estimate and the observed activity have now converged.
The interval is the familiar problem. The fix has been out since early June, and exploitation was confirmed publicly in August. Research on how quickly attackers move suggests defenders rarely get that long: CrowdStrike reported that most public exploits are weaponized within 48 hours.
What you should do
Apply Progress' update. For US federal civilian agencies this is not optional: Binding Operational Directive 26-04 requires them to prioritize rapid remediation of KEV listed vulnerabilities on publicly exposed assets that grant total control of the asset after exploitation, and it also sets expectations for checking whether a system was already compromised before the patch went on. CISA encourages every other organization to work the same way.
Because the patch has been available for two months while exploitation was underway, patching alone is not a clean bill of health. Anyone who was running an exposed, unpatched LoadMaster in that window should look for signs of prior compromise on the appliance itself, including unexpected configuration changes, new or altered administrative accounts, and outbound connections from a device that normally only answers inbound traffic. If the appliance terminates TLS, treat the certificates and keys it holds as potentially exposed.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.