Affected Systems

Progress Kemp LoadMaster GA v7.2.63.1 and older, LTSF v7.2.54.17 and older; MOVEit WAF all versions before GA v7.2.63.2. Approximately 300 instances exposed online. Used by Fortune 500 companies and government agencies including Amazon and U.S. Air Force.

Exploitation Status

Active exploitation confirmed. CISA added CVE-2026-8037 to Known Exploited Vulnerabilities catalog on August 9, 2026. No details on threat actors or attack campaigns disclosed.

Business Impact

Unauthenticated remote command execution on LoadMaster ADC appliances via unsanitized API inputs. Attackers gain full system control over critical infrastructure managing web traffic distribution and application availability. High-value targets include Fortune 500 enterprises and government entities. Compromise enables traffic interception, service disruption, lateral movement, and data exfiltration.

Urgency

🔴 Immediate

Recommended Actions

  • Immediately upgrade Progress Kemp LoadMaster to GA v7.2.63.2 or later (LTSF v7.2.54.18 or later for long-term support deployments)
  • Upgrade MOVEit WAF to GA v7.2.63.2 or later if deployed in your environment
  • Review LoadMaster API access logs for suspicious unauthenticated requests to command endpoints between June 2026 and present
  • Restrict network access to LoadMaster management interfaces using firewall rules or VPN-only access until patching is complete
  • Conduct forensic review of any unpatched LoadMaster systems for indicators of compromise including unauthorized user accounts, configuration changes, or unexpected processes