Critical Command Injection (CVE‑2026‑8037) in Progress Kemp LoadMaster Added to CISA KEV After 792 Exploit Attempts
What It Is — A critical‑severity command‑injection flaw (CVE‑2026‑8037) in the LoadMaster application delivery controller allows an unauthenticated attacker to execute arbitrary OS commands on the appliance.
Exploitability — Actively exploited in the wild; CISA has logged 792 distinct exploit attempts and placed the flaw in its Known Exploited Vulnerabilities (KEV) catalog. CVSS v3.1 base score 9.6 (Critical).
Affected Products — Progress Kemp LoadMaster (all supported versions prior to the vendor‑released patch).
Why It Matters for Compliance & Audit Readiness
- Unpatched network‑infrastructure devices constitute a control gap under SOC 2 CC6.1 (Change Management) and CC7.1 (System Operations).
- Continuous evidence of patch‑management and configuration compliance is required to demonstrate due diligence to auditors and enterprise customers.
- A breach stemming from this flaw would trigger data‑exposure investigations, impacting the organization’s risk‑assessment and incident‑response documentation.
Recommended Actions
- Verify your LoadMaster version against the vendor’s advisory and apply the latest security patch immediately.
- Update your asset inventory to flag LoadMaster instances as high‑risk assets requiring weekly compliance checks.
- Map the vulnerability to SOC 2 controls (CC6.1, CC7.1) and capture remediation evidence in your continuous‑compliance platform.
- Enable automated vulnerability scanning for all load‑balancer appliances and integrate findings into your audit evidence repository.
Source: The Hacker News