Circuit Wire — a daily news update from the Circuit.
The Cybersecurity and Infrastructure Security Agency added a critical flaw in Progress Software's Kemp LoadMaster load balancer to its catalog of actively exploited vulnerabilities on Friday, August 7, ordering federal civilian agencies to patch within three days, according to BleepingComputer. Hackers have been probing the flaw since researchers published technical details in late June.
The vulnerability, tracked as CVE-2026-8037 and rated 9.6 out of 10 in severity, lets an unauthenticated attacker run arbitrary commands on unpatched LoadMaster appliances by sending unsanitized input to several API endpoints. Progress Software released fixes in June for Kemp LoadMaster GA version 7.2.63.1 and earlier and LTSF version 7.2.54.17 and earlier, and confirmed the flaw also affects every version of its MOVEit Web Application Firewall before GA version 7.2.63.2.
LoadMaster is used to distribute web traffic and keep applications running for companies and government agencies including Amazon and the US Air Force. Progress says roughly 80 percent of Fortune 500 companies use its products in some form, with more than 100,000 LoadMaster deployments worldwide. Threat intelligence group Shadowserver counted nearly 300 Kemp LoadMaster instances still exposed to the open internet, though it is unclear how many have already been patched or are decoy systems set up to study attackers.
The patching order applies only to federal civilian agencies under Binding Operational Directive 26-04, which set today, August 10, as the deadline to secure affected servers. CISA said in its advisory that this type of vulnerability is a frequent attack vector for malicious cyber actors and urged all organizations running LoadMaster, not just government users, to apply the patch immediately. The warning follows a separate incident last month in which Progress told customers using its ShareFile Storage Zone Controllers to take servers offline over a different credible external security threat, which the company later resolved with a patch for a high-severity zero-day flaw.
Want a weekly roundup of the major stories shaping the security industry? The On The Circuit newsletter is read by more than 12,000 protection professionals.
Spotted something we should cover? Send tips and feedback via circuit-magazine.com.

