HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

Command Injection in Progress LoadMaster (CVE‑2026‑8037) Added to CISA KEV Catalog

CISA has added CVE‑2026‑8037, a remote command‑injection bug in Kemp Progress LoadMaster, to its Known Exploited Vulnerabilities catalog. Organizations must prioritize remediation to meet SOC 2 vulnerability‑management requirements and maintain a defensible audit trail.

LiveThreat™ Intelligence · 📅 August 08, 2026· 📰 cisa.gov
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
cisa.gov

Command Injection in Progress LoadMaster (CVE‑2026‑8037) Added to CISA KEV Catalog

What It Is — CISA has listed CVE‑2026‑8037, a command‑injection flaw in Kemp Progress LoadMaster appliances, in its Known Exploited Vulnerabilities (KEV) catalog after confirming active exploitation in the wild.

Exploitability — Public evidence shows attackers can execute arbitrary OS commands remotely, granting full control of the load balancer. The vendor has issued a CVSS v3.1 base score of 8.6 (High).

Affected Products — Kemp Technologies Progress LoadMaster (all supported versions prior to the August 2026 security patch).

Why It Matters for Compliance & Audit Readiness

  • SOC 2 CC6.1 & CC7.1 require documented vulnerability‑management processes; a KEV‑listed flaw must be tracked, prioritized, and remediated with auditable evidence.
  • Failure to patch a known‑exploited vulnerability can be cited as a control deficiency during a SOC 2 audit, jeopardizing the “Security” trust principle.
  • Continuous evidence of remediation (e.g., ticketing, patch‑status logs) satisfies both internal risk programs and external regulator expectations for risk‑based patch prioritization.

Recommended Actions

  • Inventory all LoadMaster instances and verify version exposure.
  • Apply the vendor‑released patch immediately; document the change in your change‑management system.
  • Record remediation evidence (patch logs, ticket closure) in a centralized compliance repository for SOC 2 audit review.
  • Update your vulnerability‑risk register to reflect the KEV status and re‑prioritize any related controls.

Source: CISA Advisory – 2026‑08‑07

📰 Original Source
https://www.cisa.gov/news-events/alerts/2026/08/07/cisa-adds-one-known-exploited-vulnerability-catalog

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →