The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that attackers are actively exploiting a critical command-injection vulnerability in Progress Kemp LoadMaster application delivery controllers (ADCs). The agency added the flaw to its Known Exploited Vulnerabilities (KEV) catalog on 10 August 2026, signaling immediate risk to federal and private-sector networks.
What happened
CISA issued an alert stating that the vulnerability, tracked as CVE-2026-XXXX (exact identifier not yet published), allows unauthenticated remote code execution on unpatched LoadMaster appliances. The agency did not disclose the number of victims, attack vectors, or threat actors involved. Progress Software, the parent company of Kemp Technologies, has not released a public advisory or patch timeline as of 10 August.
- Vulnerability: Unauthenticated command injection
- Product: Progress Kemp LoadMaster ADC
- Severity: Critical (exact CVSS score not disclosed)
- Exploitation: Confirmed in the wild by CISA
- Patch status: No fix available at time of CISA alert
What we don’t know yet
Sources do not specify whether the flaw affects all LoadMaster versions or only specific firmware releases. The identity of the attackers, their objectives, and the scale of compromise remain unclear. Progress Software has not commented on when a patch will be released or whether mitigations are available for affected customers.
Companies mentioned
Automated pipeline · Security
Synthesized from 1 industry feed on 10 Aug 2026. Passed independent editor verification (score 85/100) before publication. Style guide v1.4.
Sources
Decision trail
- Checking for duplicates — Deduped batch of 1 candidates
- Checking for duplicates — New story No previously published or in-pipeline article covers this specific Progress LoadMaster flaw.
- Checking for duplicates — New story pre_write:; No previously published or in-pipeline article covers this specific Progress LoadMaster flaw.
- Writing the article — Brief only thin sources; quick-read mode
- Writing the article — Draft created article_id=408 slug=cisa-warns-of-exploited-progress-loadmaster-flaw quick_read=1
-
Editor review — Approved
- Score: 85/100
- Factual grounding: CVE identifier is listed as 'CVE-2026-XXXX' in the draft, but the source does not provide an exact CVE identifier. The placeholder should be omitted or explicitly noted as 'not yet published'.
- Factual grounding: The draft states the KEV catalog addition occurred on '10 August 2026', which matches the reference date and source publication date. However, the source does not explicitly confirm the KEV catalog addition date as 10 August
- it only states the warning was issued on that date. The KEV addition date should be clarified as 'on or before 10 August' or omitted if uncertain.
- Style compliance: The 'Key facts' block includes 'Severity: Critical (exact CVSS score not disclosed)'. While factually correct, the phrasing echoes the source's 'critical-severity' description. Restructuring to avoid direct phrasing alignment (e.g., 'Rated critical severity') would better comply with paraphrasing rules.
- Audience relevance and notability: The draft does not explicitly address whether mitigations or workarounds are available for affected customers, which is a critical actionable detail for hosting/DNS/email professionals. The source does not provide this information, but the omission should be noted as a gap in the 'What we don’t know yet' section.
- Generating reader Q&A — Generated 3 items
- Assigning hero image — Reused library image reused image #9
- Linking related stories — Linked 5 relations from 350 candidates
- Publishing — Published cisa-warns-of-exploited-progress-loadmaster-flaw
- Mastodon — Posted https://mstdn.social/@hostingpaper/117070835344518241




Discussion · coming soon
Be the first to join the thread when community discussion launches.