What happened
The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-8037 to its Known Exploited Vulnerabilities catalog on Friday, August 7, confirming that attackers are actively using it. The bug is a command-injection flaw in Progress Kemp LoadMaster, a load-balancer appliance that sits in front of websites and applications to distribute traffic. Rated 9.6 out of 10, it lets an unauthenticated attacker run arbitrary commands on the appliance through unsanitized input in several endpoints. Telemetry from KEVIntel recorded 792 exploitation attempts over 41 days, coming from 65 unique IP addresses across 18 countries, with the most recent activity on August 4. Vulnerable releases include LoadMaster GA 7.2.63.1 and older and the LTSF branch 7.2.54.17 and older. Federal civilian agencies were ordered to apply fixes by August 10, one of the shortest turnarounds the directive allows.
Why it matters for your business
Most small businesses do not buy load balancers directly, but the hosting companies, managed service providers, and larger partners that run your websites and applications often do. An appliance like this sits at the edge of the network handling all incoming traffic, which is exactly why attackers scan for it: compromise the front door and you are positioned to intercept traffic or move inward. The three-day federal deadline is CISA's way of saying this one is being used now, not someday.
What to do about it
- If your organization runs LoadMaster, patch to a fixed release immediately and check the appliance for signs of tampering
- If your website or app is hosted by an MSP or hosting provider, ask a simple question: what sits in front of our site, and is it patched for CVE-2026-8037?
- Make edge equipment part of your standing patch conversation; firewalls, VPNs, and load balancers are the most attacked category of business infrastructure this year
