Known Exploited Vulnerabilities
Active exploits push Progress LoadMaster flaw onto CISA's must-patch list
CISA's KEV catalog now includes CVE-2026-8037, an actively exploited command injection flaw in Progress LoadMaster. Under BOD 26-04, the entry turns a one-line advisory into a federal patch priority, and CISA urges every organization to treat the list the same way.
Emmanuel Fabrice Omgbwa Yasse AI-assisted
2026-08-10 · 3 min read

CISA has added CVE-2026-8037 to its Known Exploited Vulnerabilities catalog. The entry covers a command injection vulnerability in Progress LoadMaster, and the agency says it is acting on evidence of active exploitation. Catalog additions are not ordinary advisories. For federal agencies, they start a remediation clock.
The clock comes from Binding Operational Directive 26-04. The directive applies to Federal Civilian Executive Branch agencies and requires them to prioritize rapid remediation of high-risk KEV-listed CVEs on publicly exposed assets that grant total control of the asset after exploitation, while lower-risk items can be deferred. It also expects agencies to check whether threat actors compromised systems before the patch was applied, a step that usually gets lost in an emergency. That step is why a KEV entry now means more than patching.
Why one catalog line becomes an agency deadline
BOD 26-04 changes what a KEV entry means. The catalog stops being a watch list and becomes a work queue with its own triage rules. Agencies no longer get to decide which exploited flaws deserve speed; the directive picks the category for them: publicly exposed, total control, actively exploited. Those are the bugs most likely to become beachheads, and the classification removes the softer judgment calls that used to slow patching down.
Command injection is one of the more direct flaw classes. If successfully exploited, it lets an attacker run operating system commands on the vulnerable host. Here the notice names the product and the CVE, then stops. There are no affected versions on record and no indication of who is behind the exploitation.
CISA's guidance extends beyond government. The notice repeats the standing recommendation that all organizations adopt risk-based vulnerability management and prioritize remediation of catalog-listed flaws, not only the ones that touch federal systems. The catalog has become a de facto industry list of what attackers are actually using, which is more useful than most severity scores.
The catalog's recent additions, in context
The LoadMaster entry is one update in a steady series. The same wave of catalog notices includes a hard-coded password vulnerability in Cisco Secure Firewall Management Center (CVE-2026-20316), a case we wrote up as evidence that patching alone is no longer enough, plus an improper authentication issue in Check Point SmartConsole (CVE-2026-16232) and a deserialization flaw in Microsoft SharePoint (CVE-2026-50522).
| CVE | Product | Flaw type |
|---|---|---|
| CVE-2026-8037 | Progress LoadMaster | Command injection |
| CVE-2026-20316 | Cisco Secure Firewall Management Center | Use of hard-coded password |
| CVE-2026-16232 | Check Point SmartConsole | Improper authentication |
| CVE-2026-50522 | Microsoft SharePoint | Deserialization of untrusted data |
What connects these entries is not severity scoring. Each was added on the same basis: evidence of active exploitation. That is the catalog's admission bar, alongside a valid CVE ID and clear mitigation guidance, and CISA keeps a nomination form open for organizations that know of exploited flaws missing from the list.
What the notice leaves out
The advisory is terse by design, and the format has consequences. Teams get a product name, a CVE, and a vulnerability class, with none of the details that help with triage. The responsible move is to check whether the LoadMaster deployment matches the entry's conditions, follow the vendor's mitigation guidance, and treat the catalog as a priority queue rather than waiting for a more dramatic alert.
The operational read is short. Patch what the catalog lists even when the vendor notice feels routine. If a system was exposed before the patch went on, look for signs of compromise before declaring the case closed. That is the exact check BOD 26-04 demands of federal agencies, and it is why a KEV entry never ends at the patch. Those agencies are now required to prioritize this entry; everyone else gets the same list and the same logic. The list is built on one fact: these flaws are being exploited right now.
- Source : Active exploits push Progress LoadMaster flaw onto CISA's must-patch list — 2026-08-07
Get the tech essentials in 3 minutes every morning
One email, every weekday, with what actually matters in AI and tech.