type: incident ยท created: 2026-08-08 ยท updated: 2026-08-08 ยท tags: [incident, kev, rce, zero-day, cisa, sector-government] ยท confidence: high ยท affected_sectors: [technology, government] ยท au_impact: true
CISA Adds Progress LoadMaster RCE (CVE-2026-8037) to Known Exploited Vulnerabilities Catalogue
CISA added CVE-2026-8037, an unauthenticated command-injection RCE in Progress LoadMaster, to its Known Exploited Vulnerabilities (KEV) catalogue (added 7 Aug, due 10 Aug).
Key Details
- Source: CISA
- Date: 2026-08-07
- Reliability: Tier 1/4 โ Official / first-party
- Nature: KEV catalogue addition for an actively relevant zero-day
Summary
The flaw allows an unauthenticated attacker to execute arbitrary commands on the LoadMaster appliance via unsanitised input in multiple command endpoints. Progress LoadMaster is widely deployed as an application-delivery/load-balancing appliance in enterprise and government networks, making prompt patching under BOD 26-04 essential.
Analysis
LoadMaster is widely deployed in Australian enterprise data centres and government gateways โ CVE-2026-8037 is unauthenticated RCE and should be patched under the Essential Eight patching schedule.
Related Pages
- Cve 2026 8037 Progress Loadmaster Rce โ The LoadMaster CVE page
Sources: raw/digests/Cyber-Digest-2026-08-08