Organizations using Progress LoadMaster should apply vendor-provided patches immediately. Federal Civilian Executive Branch agencies must follow the remediation requirements and pre-patch compromise verification procedures outlined in BOD 26-04. All other organizations are encouraged to adopt risk-based vulnerability management practices and prioritize remediation of KEV Catalog vulnerabilities on publicly exposed assets.
Quick answers
What is CVE-2026-8037?
Organizations using Progress LoadMaster should apply vendor-provided patches immediately. Federal Civilian Executive Branch agencies must follow the remediation requirements and pre-patch compromise verification procedures outlined in BOD 26-04. All other organizations are encouraged to adopt risk-based vulnerability management practices and prioritize remediation of KEV Catalog vulnerabilities on publicly exposed assets.
How severe is CVE-2026-8037?
high
Is CVE-2026-8037 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-8037 be mitigated?
Organizations using Progress LoadMaster should apply vendor-provided patches immediately. Federal Civilian Executive Branch agencies must follow the remediation requirements and pre-patch compromise verification procedures outlined in BOD 26-04. All other organizations are encouraged to adopt risk-based vulnerability management practices and prioritize remediation of KEV Catalog vulnerabilities on publicly exposed assets.
CVSS
—
Vendor
Progress
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
LoadMaster
Mitigation
Organizations using Progress LoadMaster should apply vendor-provided patches immediately. Federal Civilian Executive Branch agencies must follow the remediation requirements and pre-patch compromise verification procedures outlined in BOD 26-04. All other organizations are encouraged to adopt risk-based vulnerability management practices and prioritize remediation of KEV Catalog vulnerabilities on publicly exposed assets.
On August 7, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-8037, a Progress LoadMaster command injection vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog. The addition is based on evidence of active exploitation in the wild. The vulnerability affects Progress LoadMaster systems and poses significant risk to Federal Civilian Executive Branch (FCEB) agencies, particularly those with publicly exposed instances that could grant total asset control post-exploitation. CISA's Binding Operational Directive 26-04 requires affected federal agencies to prioritize rapid remediation and verify whether systems were compromised before patching.