Command Injection in Progress LoadMaster (CVE‑2026‑8037) Added to CISA KEV Catalog
What It Is — CISA has listed CVE‑2026‑8037, a command‑injection flaw in Kemp Progress LoadMaster appliances, in its Known Exploited Vulnerabilities (KEV) catalog after confirming active exploitation in the wild.
Exploitability — Public evidence shows attackers can execute arbitrary OS commands remotely, granting full control of the load balancer. The vendor has issued a CVSS v3.1 base score of 8.6 (High).
Affected Products — Kemp Technologies Progress LoadMaster (all supported versions prior to the August 2026 security patch).
Why It Matters for Compliance & Audit Readiness
- SOC 2 CC6.1 & CC7.1 require documented vulnerability‑management processes; a KEV‑listed flaw must be tracked, prioritized, and remediated with auditable evidence.
- Failure to patch a known‑exploited vulnerability can be cited as a control deficiency during a SOC 2 audit, jeopardizing the “Security” trust principle.
- Continuous evidence of remediation (e.g., ticketing, patch‑status logs) satisfies both internal risk programs and external regulator expectations for risk‑based patch prioritization.
Recommended Actions
- Inventory all LoadMaster instances and verify version exposure.
- Apply the vendor‑released patch immediately; document the change in your change‑management system.
- Record remediation evidence (patch logs, ticket closure) in a centralized compliance repository for SOC 2 audit review.
- Update your vulnerability‑risk register to reflect the KEV status and re‑prioritize any related controls.
Source: CISA Advisory – 2026‑08‑07