Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-08 ยท updated: 2026-08-08 ยท tags: [incident, kev, rce, zero-day, cisa, sector-government] ยท confidence: high ยท affected_sectors: [technology, government] ยท au_impact: true

CISA Adds Progress LoadMaster RCE (CVE-2026-8037) to Known Exploited Vulnerabilities Catalogue

CISA added CVE-2026-8037, an unauthenticated command-injection RCE in Progress LoadMaster, to its Known Exploited Vulnerabilities (KEV) catalogue (added 7 Aug, due 10 Aug).

Key Details

  • Source: CISA
  • Date: 2026-08-07
  • Reliability: Tier 1/4 โ€” Official / first-party
  • Nature: KEV catalogue addition for an actively relevant zero-day

Summary

The flaw allows an unauthenticated attacker to execute arbitrary commands on the LoadMaster appliance via unsanitised input in multiple command endpoints. Progress LoadMaster is widely deployed as an application-delivery/load-balancing appliance in enterprise and government networks, making prompt patching under BOD 26-04 essential.

Analysis

LoadMaster is widely deployed in Australian enterprise data centres and government gateways โ€” CVE-2026-8037 is unauthenticated RCE and should be patched under the Essential Eight patching schedule.

Related Pages

Sources: raw/digests/Cyber-Digest-2026-08-08