What happened

On 7 August, the US Cybersecurity and Infrastructure Security Agency added CVE-2026-8037 to its Known Exploited Vulnerabilities catalogue, saying there is evidence of active exploitation. The vulnerability is in Progress LoadMaster, an application-delivery and load-balancing appliance. CISA describes it as command injection and tells organisations to apply the vendor's mitigations, while prioritising catalogue vulnerabilities through risk-based vulnerability management.

The CVE record published by Progress says unauthenticated input to multiple API command endpoints is not properly sanitised. A successful attacker can inject operating-system commands and achieve remote code execution on the appliance. Progress rates the issue Critical with a CVSS 3.1 base score of 9.6. That rating describes technical impact; CISA's separate catalogue entry is the evidence that exploitation is occurring. Neither source attributes the activity or says every exposed appliance has been compromised.

[1][2]

Who is affected

Progress lists two affected LoadMaster branches: releases from 7.2.60.0 up to, but not including, 7.2.63.2; and releases from 7.2.45.12 up to, but not including, 7.2.54.18. The record also lists ECS Connection Manager, Object Scale Connection Manager and MOVEit WAF from 7.2.60.0 up to, but not including, 7.2.63.2. Other versions are marked unaffected in the vendor's record.

Businesses should compare the complete installed version, not only the major or minor branch. They should also check virtual, hardware, cloud and standby instances recorded outside the main server inventory. Where a managed-service provider controls the appliance, the customer still needs written confirmation of the installed release and the date remediation was completed.

[2]

What defenders should do

Identify every affected Progress appliance and record its full version, owner, administrative route and exposure. Move affected systems to at least 7.2.63.2, or 7.2.54.18 for the older LoadMaster branch, following the vendor's supported update process. Test application delivery, health checks, certificates, authentication and monitoring after the change, and keep a documented rollback route.

Restrict administrative and API access to approved management networks while the update is completed. This reduces opportunity but is not a substitute for the fixed release. Because CISA reports exploitation, review relevant appliance and surrounding-system logs for unexpected administrative activity or changes, preserve useful evidence, and escalate credible signs through the incident-response process. Do not treat a successful update as proof that earlier access did not occur.

CISA's remediation deadlines bind US federal agencies, not UK companies. The useful signal for a UK business is the verified exploitation status: prioritise affected and reachable appliances according to operational risk, and document any delay with an owner and a near-term completion date.

  • Find all LoadMaster and related Progress appliances and capture full versions.
  • Update affected branches to the vendor's fixed release boundary.
  • Limit management and API reachability to approved networks.
  • Review for unexpected activity and preserve evidence where warranted.
  • Obtain dated remediation confirmation from service providers.
[1][2]

The Beekeeper view

Load balancers can become operational furniture: essential, rarely touched and absent from ordinary endpoint patching. Yet they sit where external traffic, certificates and internal services meet. The practical risk is therefore not only the flaw; it is an appliance whose owner, version or maintenance route cannot be established quickly.

For UK businesses, the durable fix is a small control loop: keep edge appliances in the asset register, give each one an accountable owner, restrict management paths, monitor administrative change and rehearse supported updates. That turns the next urgent advisory from a search exercise into a controlled maintenance decision.

[1][2]
An exploited flaw in an access appliance deserves a short route from inventory to update, backed by a compromise check rather than an assumption that patching closes the history.

Primary sources

  1. CISA Adds One Known Exploited Vulnerability to Catalog — CISA, 7 August 2026
  2. CVE-2026-8037 record — Progress Software, 4 June 2026

Beekeeper field notes summarise primary advisories for a UK business audience. Always follow the affected vendor’s current instructions for your exact product and version.