HomeIntelligenceBrief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical Command Injection Vulnerability (CVE‑2026‑8037) in Progress Kemp LoadMaster Actively Exploited

CISA warns that CVE‑2026‑8037, a critical command‑injection flaw in Progress Kemp LoadMaster ADCs, is being actively exploited. Organizations must patch immediately and capture remediation evidence to satisfy SOC 2 security controls.

LiveThreat™ Intelligence · 📅 August 10, 2026· 📰 bleepingcomputer.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
bleepingcomputer.com

Critical Command Injection Vulnerability (CVE‑2026‑8037) in Progress Kemp LoadMaster Actively Exploited

What Happened — CISA has issued an alert that a critical‑severity command‑injection flaw (CVE‑2026‑8037) in Progress Kemp LoadMaster ADCs is being actively exploited. The vulnerability allows unauthenticated attackers to execute arbitrary OS commands via unsanitized API inputs on unpatched appliances.

Why It Matters for Compliance & Audit Readiness

  • The flaw bypasses the “least‑privilege” and “secure‑by‑design” controls that SOC 2 Security and Availability criteria require, highlighting the need for continuous vulnerability management.
  • Demonstrating timely patching and evidence of remediation is a core audit artifact; failure to remediate can be cited as a control deficiency in a SOC 2 audit.
  • Mapping this exploit to the “Change Management” and “System Operations” controls (CC6.1, CC7.2) provides concrete evidence for the Trust Center’s continuous‑compliance dashboard.

Who Is Affected — Enterprises that deploy LoadMaster ADCs, including technology firms, cloud service providers, and government agencies (e.g., U.S. Air Force, Fortune 500 companies).

Recommended Actions

  • Verify LoadMaster version; apply the security update (GA v7.2.63.1 / LTSF v7.2.54.17 or later) immediately.
  • Run an automated inventory scan to identify any exposed instances; document remediation dates for audit evidence.
  • Update your vulnerability‑management policy to include continuous monitoring of vendor‑issued advisories and enforce a 72‑hour patch window for critical findings.

Technical Notes — The vulnerability is a command‑injection (CVE‑2026‑8037) affecting GA v7.2.63.1 and earlier, and LTSF v7.2.54.17 and earlier. Exploitation leverages unsanitized API parameters across multiple endpoints, enabling remote code execution without authentication. Source: BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/security/cisa-warns-of-critical-progress-loadmaster-flaw-exploited-in-attacks/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →