Progress Kemp LoadMaster CVE-2026-8037
Known Exploitation, Concrete Network Indicators, Patch Boundaries, and U.S. SMB Response
- Field
- User Topic
- Value
- Progress Kemp LoadMaster CVE-2026-8037 terminology, exploitation, CISA KEV status, U.S. SMB relevance, and cyber-insurance implications
- Field
- Interpreted Questions
- Value
- What do Progress, Kemp, and LoadMaster mean in the title; which products and versions are affected; what is confirmed about exploitation; what concrete indicators exist; what should defenders do now; and what ransomware or insurance conclusions are and are not supported?
- Field
- Initial Observations
- Value
- CVE-2026-8037 is a critical unauthenticated command-execution flaw reachable through the LoadMaster API when enabled. Progress disclosed fixes in June; public technical analysis and proof-of-concept code appeared June 29; eSentire observed unsuccessful exploitation attempts beginning the same day; CISA added the CVE to KEV on August 7. No retained source names a responsible actor, confirms a public victim, or establishes ransomware use.1, 2, 3, 4, 5, 6
- Field
- Source Coverage
- Value
- Tier
- Tier 0 — Government and vendor primary sources
- Checked
- 7
- Candidate Hits
- 6
- Planner Selected
- 6
- Not Used
- 1
- Tier
- Tier 1 — Original technical research and observed activity
- Checked
- 5
- Candidate Hits
- 3
- Planner Selected
- 3
- Not Used
- 2
- Tier
- Tier 2 — Sector and insurance context
- Checked
- 3
- Candidate Hits
- 2
- Planner Selected
- 2
- Not Used
- 1
- Tier
- Tier 3 — Established security reporting
- Checked
- 3
- Candidate Hits
- 0
- Planner Selected
- 0
- Not Used
- 3
- Tier
- Tier 4 — Community and practitioner reporting
- Checked
- 3
- Candidate Hits
- 0
- Planner Selected
- 0
- Not Used
- 3
- Tier
- Tier 5 — Framework and taxonomy
- Checked
- 3
- Candidate Hits
- 2
- Planner Selected
- 2
- Not Used
- 1
- Tier
- Tier 6 — Social and forum leads
- Checked
- 2
- Candidate Hits
- 0
- Planner Selected
- 0
- Not Used
- 2
- Tier
- Tier 7 — Aggregators and search-only leads
- Checked
- 2
- Candidate Hits
- 0
- Planner Selected
- 0
- Not Used
- 2
- Tier
- Tier 8 — Unverified or excluded material
- Checked
- 2
- Candidate Hits
- 0
- Planner Selected
- 0
- Not Used
- 2
Tier Checked Candidate Hits Planner Selected Not Used Tier 0 — Government and vendor primary sources 7 6 6 1 Tier 1 — Original technical research and observed activity 5 3 3 2 Tier 2 — Sector and insurance context 3 2 2 1 Tier 3 — Established security reporting 3 0 0 3 Tier 4 — Community and practitioner reporting 3 0 0 3 Tier 5 — Framework and taxonomy 3 2 2 1 Tier 6 — Social and forum leads 2 0 0 2 Tier 7 — Aggregators and search-only leads 2 0 0 2 Tier 8 — Unverified or excluded material 2 0 0 2
- Field
- Evidence Boundary
- Value
- CISA controls KEV status and required federal action. Progress controls product and fixed-version guidance. NVD controls the consolidated vulnerability record. watchTowr controls its technical research and proof-of-concept timeline. eSentire controls its observed-attempt statement and published IPs; it explicitly says its observed attempts were unsuccessful. H-ISAC and Canada provide corroborating advisory context. At-Bay portfolio data is used only for broad insurance and SMB loss context.
| Field | Value | ||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| User Topic | Progress Kemp LoadMaster CVE-2026-8037 terminology, exploitation, CISA KEV status, U.S. SMB relevance, and cyber-insurance implications | ||||||||||||||||||||||||||||||||||||||||||||||||||
| Interpreted Questions | What do Progress, Kemp, and LoadMaster mean in the title; which products and versions are affected; what is confirmed about exploitation; what concrete indicators exist; what should defenders do now; and what ransomware or insurance conclusions are and are not supported? | ||||||||||||||||||||||||||||||||||||||||||||||||||
| Initial Observations | CVE-2026-8037 is a critical unauthenticated command-execution flaw reachable through the LoadMaster API when enabled. Progress disclosed fixes in June; public technical analysis and proof-of-concept code appeared June 29; eSentire observed unsuccessful exploitation attempts beginning the same day; CISA added the CVE to KEV on August 7. No retained source names a responsible actor, confirms a public victim, or establishes ransomware use.1, 2, 3, 4, 5, 6 | ||||||||||||||||||||||||||||||||||||||||||||||||||
| Source Coverage |
| ||||||||||||||||||||||||||||||||||||||||||||||||||
| Evidence Boundary | CISA controls KEV status and required federal action. Progress controls product and fixed-version guidance. NVD controls the consolidated vulnerability record. watchTowr controls its technical research and proof-of-concept timeline. eSentire controls its observed-attempt statement and published IPs; it explicitly says its observed attempts were unsuccessful. H-ISAC and Canada provide corroborating advisory context. At-Bay portfolio data is used only for broad insurance and SMB loss context. |
Use this table to decide whether a LoadMaster deployment is exposed, what evidence to preserve, and which conclusions remain unsupported. The terminology row explains the title; the remaining rows preserve the existing vulnerability and exploitation boundaries.1, 2, 3, 5, 6, 11, 12
KEV Added
Aug 7
CISA added CVE-2026-8037 to the Known Exploited Vulnerabilities catalog.
Severity
Critical
NVD displays 9.8 and Progress 9.6 CVSS v3.1 assessments.
Authentication
None
The vulnerable API path can be reached without valid credentials when enabled.
GA Fixed Build
7.2.63.2
GA 7.2.63.1 and prior are affected in the retained advisory boundary.
LTSF Fixed Build
7.2.54.18
LTSF 7.2.54.17 and prior are affected in the retained advisory boundary.
Named Actor
None
The retained evidence does not support actor or ransomware attribution.
- Decision Question
- What does the title mean?
- Current Source-backed Finding
- Progress is the vendor. Kemp is the legacy product-brand lineage that Progress acquired in 2021. LoadMaster is the application delivery controller and load-balancer product line.
- Decision / Evidence Needed
- Use the full name for product identification; do not read the three terms as three separate affected products.
- Decision Question
- Is the deployment exposed?
- Current Source-backed Finding
- The documented path requires affected LoadMaster API functionality to be enabled and reachable.
- Decision / Evidence Needed
- Record exact build, API state, interface and source-network reachability; do not infer exposure from product ownership alone.
- Decision Question
- What closes the vulnerable condition?
- Current Source-backed Finding
- GA 7.2.63.1 and prior and LTSF 7.2.54.17 and prior are within the retained affected boundary.
- Decision / Evidence Needed
- Verify GA 7.2.63.2 or later, or LTSF 7.2.54.18 or later, against current Progress guidance.
- Decision Question
- What is known about exploitation?
- Current Source-backed Finding
- CISA lists the CVE in KEV. eSentire observed attempts beginning June 29 and said its observed attempts were unsuccessful.
- Decision / Evidence Needed
- Prioritize remediation while keeping ecosystem exploitation separate from any local compromise conclusion.
- Decision Question
- What can defenders hunt now?
- Current Source-backed Finding
- Three attacker IPs and the /accessv2 request surface are public; domains, malicious URLs, filenames and file hashes are not public in retained reliable sources.
- Decision / Evidence Needed
- Correlate the IPs and HTTP activity with appliance, identity, configuration, process and network telemetry.
- Decision Question
- What impact is confirmed?
- Current Source-backed Finding
- No retained source names a victim or confirms data theft, ransomware, downstream access or service disruption from this CVE.
- Decision / Evidence Needed
- Determine impact from owned forensic evidence, reachable trust, served applications, logs and continuity testing.
| Decision Question | Current Source-backed Finding | Decision / Evidence Needed | Sources |
|---|---|---|---|
| What does the title mean? | Progress is the vendor. Kemp is the legacy product-brand lineage that Progress acquired in 2021. LoadMaster is the application delivery controller and load-balancer product line. | Use the full name for product identification; do not read the three terms as three separate affected products. | Primary vendor product and acquisition records11, 12 |
| Is the deployment exposed? | The documented path requires affected LoadMaster API functionality to be enabled and reachable. | Record exact build, API state, interface and source-network reachability; do not infer exposure from product ownership alone. | Vendor and technical research3, 4, 5 |
| What closes the vulnerable condition? | GA 7.2.63.1 and prior and LTSF 7.2.54.17 and prior are within the retained affected boundary. | Verify GA 7.2.63.2 or later, or LTSF 7.2.54.18 or later, against current Progress guidance. | Vendor, NVD, Canada2, 3, 6 |
| What is known about exploitation? | CISA lists the CVE in KEV. eSentire observed attempts beginning June 29 and said its observed attempts were unsuccessful. | Prioritize remediation while keeping ecosystem exploitation separate from any local compromise conclusion. | CISA and eSentire1, 5 |
| What can defenders hunt now? | Three attacker IPs and the /accessv2 request surface are public; domains, malicious URLs, filenames and file hashes are not public in retained reliable sources. | Correlate the IPs and HTTP activity with appliance, identity, configuration, process and network telemetry. | eSentire and watchTowr4, 5 |
| What impact is confirmed? | No retained source names a victim or confirms data theft, ransomware, downstream access or service disruption from this CVE. | Determine impact from owned forensic evidence, reachable trust, served applications, logs and continuity testing. | Government, vendor and observed-activity record1, 3, 5, 6 |
Progress Kemp LoadMaster is an application delivery controller positioned near important web and application traffic. CVE-2026-8037 allows an unauthenticated attacker to execute arbitrary commands through affected API functionality when the API is enabled. CISA added the flaw to its Known Exploited Vulnerabilities catalog on August 7, 2026. Because the appliance sits at the network edge and can see or broker critical services, an exposed vulnerable instance requires both emergency remediation and retrospective incident triage.1, 2, 3, 4, 6
The same public evidence creates different decisions for owners, operators and risk stakeholders. Each audience must keep product exposure, compromise evidence and business impact as separate questions.
- Audience
- Executive / owner
- Primary Question
- Could an exposed edge appliance interrupt critical applications or customer services?
- Decision-ready Use
- Require asset ownership, fixed-build proof, historical exposure findings and tested continuity rather than a patch-status statement alone.
- Audience
- Network / platform team
- Primary Question
- Which LoadMaster branch, build, API state, interfaces and served applications are in scope?
- Decision-ready Use
- Document topology and reachability, restrict unnecessary API access, preserve configuration and apply the correct branch-specific fix.
- Audience
- SOC / incident response
- Primary Question
- Is there owned evidence of suspicious requests, command execution, configuration change or downstream activity?
- Decision-ready Use
- Correlate public IP and HTTP leads with appliance, identity, process, application and network telemetry before declaring compromise.
- Audience
- MSP / hosting provider
- Primary Question
- Does shared administration or appliance trust create customer-by-customer exposure?
- Decision-ready Use
- Scope tenants, credentials, certificates, management paths and disclosure duties separately; do not infer every tenant was affected.
- Audience
- Legal / insurance / continuity
- Primary Question
- What is confirmed about access, impact and interruption, and what remains only plausible?
- Decision-ready Use
- Use owned forensic and business records for notice and coverage decisions; retain portfolio statistics as context, not CVE-specific causation.
| Audience | Primary Question | Decision-ready Use | Sources |
|---|---|---|---|
| Executive / owner | Could an exposed edge appliance interrupt critical applications or customer services? | Require asset ownership, fixed-build proof, historical exposure findings and tested continuity rather than a patch-status statement alone. | Government and vendor1, 2, 3, 6 |
| Network / platform team | Which LoadMaster branch, build, API state, interfaces and served applications are in scope? | Document topology and reachability, restrict unnecessary API access, preserve configuration and apply the correct branch-specific fix. | Vendor and research3, 4, 5 |
| SOC / incident response | Is there owned evidence of suspicious requests, command execution, configuration change or downstream activity? | Correlate public IP and HTTP leads with appliance, identity, process, application and network telemetry before declaring compromise. | Technical and observed activity4, 5 |
| MSP / hosting provider | Does shared administration or appliance trust create customer-by-customer exposure? | Scope tenants, credentials, certificates, management paths and disclosure duties separately; do not infer every tenant was affected. | Product and technical context2, 3, 4, 5 |
| Legal / insurance / continuity | What is confirmed about access, impact and interruption, and what remains only plausible? | Use owned forensic and business records for notice and coverage decisions; retain portfolio statistics as context, not CVE-specific causation. | Government, eSentire and At-Bay1, 5, 10 |
- Read the product name correctly: In this brief, Progress is the current vendor, Kemp is the legacy product-brand lineage that Progress acquired in 2021, and LoadMaster is the application delivery controller and load-balancer product line. The title preserves the recognizable product lineage; it does not name three separate affected products.11, 12
- Patch and investigate now: CVE-2026-8037 is in CISA KEV and enables unauthenticated command execution against affected API-enabled LoadMaster appliances. Upgrade GA deployments to 7.2.63.2 or later and LTSF deployments to 7.2.54.18 or later, following current Progress guidance.1, 2, 3, 5, 6
- Treat historical exposure as an incident-triage question: Public proof-of-concept code and observed exploitation attempts appeared June 29. Preserve and review appliance, API, authentication, configuration, process, and network evidence before concluding that patch completion resolved risk.4, 5
- Hunt concrete indicators without over-attributing: eSentire published 192.42.116.58, 192.42.116.105, and 146.70.139.154 as attacker IPs. Search historical telemetry for connections to or from those addresses, then validate timing and behavior; an IP match alone does not establish successful exploitation or actor identity.5
- Scope the edge-appliance blast radius: Determine which applications, certificates, credentials, administrative paths, networks, tenants, and customer services the appliance could reach or influence. Successful appliance access can become an availability, confidentiality, integrity, and downstream-trust event.2, 3, 4, 5
- Keep ransomware and insurance claims evidence-bound: No retained source confirms ransomware use of CVE-2026-8037. At-Bay data shows that remote-access infrastructure and downtime drive material SMB ransomware losses, but those portfolio findings are context—not LoadMaster-specific causation.1, 5, 10
The name in the title describes one vendor-and-product lineage. Progress is the current software vendor. Kemp is the legacy product brand and company lineage that Progress acquired in 2021. LoadMaster is the application delivery controller and load-balancer product line now presented by Progress as Progress Kemp LoadMaster. This clarification is naming context only and does not modify the vulnerability's exploitation status, severity, attribution, indicators, affected versions, fixed versions, or impact boundaries.11, 12
CVE-2026-8037 is an operating-system command-injection remote-code-execution vulnerability in Progress application-delivery products. NVD states that unauthenticated attackers can exploit unsanitized input in multiple command endpoints. Technical research traces exploitation through the API, including the /accessv2 surface when enabled, and explains how flawed handling of an allocated string can introduce attacker-controlled material into a system command.2, 4, 5
Progress disclosed the issue and fixed builds in early June. watchTowr released detailed analysis and a functional proof of concept on June 29. eSentire observed exploitation attempts beginning that day and published three attacker IPs, while noting that its observed attempts were unsuccessful. H-ISAC amplified the warning July 1. Canada updated its advisory August 7 after CISA added the vulnerability to KEV.1, 3, 4, 5, 6
LoadMaster commonly sits in front of important applications and can terminate encrypted sessions, route traffic, perform health checks, and enforce application-delivery controls. A compromised appliance can disrupt service, expose configuration or secrets, alter traffic handling, and provide a foothold near internal application infrastructure. The impact must be determined from the actual deployment, permissions, routes, certificates, and logs—not from the CVE alone.2, 3, 4, 5
For an SMB or MSP, the practical concern is concentrated operational trust. One edge appliance may support customer portals, remote services, email, line-of-business applications, or multiple managed tenants. Immediate priorities are asset ownership, fixed-version verification, removal of unnecessary API reachability, evidence preservation, IOC and behavior hunting, reachable-secret rotation when warranted, and continuity testing.1, 3, 5, 6
At-Bay's 2026 portfolio report found that VPNs initiated 73% of its 2025 ransomware claims, VPN plus RDP initiated 87%, and ransomware with business interruption was three times more severe. Companies below $25 million in revenue experienced a 21% increase in ransomware frequency and a 40% increase in severity to $422,000. These statistics support prioritizing edge security and downtime readiness; they do not show that LoadMaster, CVE-2026-8037, or any specific actor caused those claims.10
No retained source names a threat actor, confirms a public victim, or associates this CVE with ransomware. Do not merge the three published IPs with unrelated infrastructure, do not infer successful exploitation from scanning alone, and do not claim breach or data loss without owned telemetry and forensic evidence.1, 3, 5, 6
- Stakeholder
- U.S. SMB
- Why It Matters
- A LoadMaster may front revenue-producing applications, portals, remote services, and customer traffic. Appliance compromise can create downtime and a trusted path toward internal services.
- Stakeholder
- MSP / hosting provider
- Why It Matters
- Shared or centrally administered edge infrastructure can concentrate customer reach and credentials.
- Stakeholder
- Insurance / risk
- Why It Matters
- At-Bay portfolio data shows remote-access infrastructure and downtime are major loss drivers, but it does not establish LoadMaster-specific ransomware causation.
- Decision
- Use the statistics to prioritize edge control and interruption readiness, not to infer a campaign.10
- Stakeholder
- SOC / incident response
- Why It Matters
- CISA's ecosystem-level KEV finding and eSentire's unsuccessful observed attempts answer different questions; neither establishes compromise of the local appliance.
| Stakeholder | Why It Matters | Decision |
|---|---|---|
| U.S. SMB | A LoadMaster may front revenue-producing applications, portals, remote services, and customer traffic. Appliance compromise can create downtime and a trusted path toward internal services. | Identify every appliance, patch immediately, preserve evidence, and test continuity.1, 2, 3, 6 |
| MSP / hosting provider | Shared or centrally administered edge infrastructure can concentrate customer reach and credentials. | Scope tenants, management trust, downstream access, and customer notification separately.2, 3, 4 |
| Insurance / risk | At-Bay portfolio data shows remote-access infrastructure and downtime are major loss drivers, but it does not establish LoadMaster-specific ransomware causation. | Use the statistics to prioritize edge control and interruption readiness, not to infer a campaign.10 |
| SOC / incident response | CISA's ecosystem-level KEV finding and eSentire's unsuccessful observed attempts answer different questions; neither establishes compromise of the local appliance. | Preserve telemetry and reconcile IP, HTTP, product, identity, host and downstream behavior before closing or escalating the incident.1, 4, 5 |
- Date / Period
- Jun 4, 2026
- Date / Period
- Jun 29, 2026
- Date / Period
- Jun 30, 2026
- Event / Meaning
- eSentire published its advisory, three attacker IPs, and the boundary that its observed attempts were unsuccessful.5
- Sources
- 5
- Date / Period
- Jul 1, 2026
- Event / Meaning
- H-ISAC/AHA amplified the active-attempt warning and urged affected organizations to verify configurations and patch.7
- Sources
- 7
- Date / Period
- Aug 7, 2026
| Date / Period | Event / Meaning | Sources |
|---|---|---|
| Jun 4, 2026 | Progress disclosed CVE-2026-8037 and the companion CVE-2026-33691 with fixed-version guidance.2, 3 | 2, 3 |
| Jun 29, 2026 | watchTowr published technical analysis and functional proof-of-concept research; eSentire began observing exploitation attempts the same day.4, 5 | 4, 5 |
| Jun 30, 2026 | eSentire published its advisory, three attacker IPs, and the boundary that its observed attempts were unsuccessful.5 | 5 |
| Jul 1, 2026 | H-ISAC/AHA amplified the active-attempt warning and urged affected organizations to verify configurations and patch.7 | 7 |
| Aug 7, 2026 | CISA added CVE-2026-8037 to KEV; the Canadian Cyber Centre published Update 2 reflecting the KEV action.1, 6 | 1, 6 |
| Aug 8, 2026 | IntelliOS published this evidence-reconciled PANDA Flash baseline with no named actor, victim, or ransomware claim.1, 2, 3, 4, 5, 6 | 1, 2, 3, 4, 5, 6 |
- Phase
- 1 — Identify exposure
- Phase
- 2 — Preserve evidence
- Phase
- 3 — Contain and patch
- Phase
- 4 — Hunt
- Phase
- 5 — Scope downstream trust
| Phase | Action | Sources |
|---|---|---|
| 1 — Identify exposure | Inventory LoadMaster and related Progress ADC products, owner, model, branch, exact build, API state, internet or partner reachability, management paths, served applications, certificates, and downstream networks.2, 3, 6 | 2, 3, 6 |
| 2 — Preserve evidence | Before destructive cleanup, retain configuration exports, API and web logs, administrative authentication, audit records, system events, network flow, DNS, proxy, firewall, EDR or NDR, and change history for the vulnerable period.1, 4, 5 | 1, 4, 5 |
| 3 — Contain and patch | Restrict unnecessary API and management reachability. Upgrade GA to 7.2.63.2 or later and LTSF to 7.2.54.18 or later, and apply current Progress guidance for other affected products.1, 3, 5, 6 | 1, 3, 5, 6 |
| 4 — Hunt | Search for the three published IPs, suspicious /accessv2 requests, unusual API activity, command or shell execution, configuration changes, new accounts or keys, certificate access, unexpected outbound traffic, and downstream authentication from appliance-adjacent sources.4, 5 | 4, 5 |
| 5 — Scope downstream trust | Determine which applications, credentials, certificates, network segments, tenants, and customer environments were reachable. Rotate secrets or certificates when evidence or uncertainty shows they could have been exposed.2, 4, 5 | 2, 4, 5 |
| 6 — Recover and report | Validate known-good configuration, application routing, monitoring, backups, failover, and service continuity. Notify counsel, insurer, customers, or regulators based on confirmed facts and contractual thresholds.1, 6, 10 | 1, 6, 10 |
- Term
- Progress / Kemp / LoadMaster
- Meaning Here
- Progress is the current vendor; Kemp is the legacy product-brand lineage acquired by Progress in 2021; LoadMaster is the application delivery controller and load-balancer product line. The combined name identifies the lineage of one product family, not three separate affected products.11, 12
- Term
- Application delivery controller (ADC)
- Meaning Here
- An edge system that distributes and manages application traffic and may terminate TLS, monitor health, switch content, or enforce web-application controls.4
- Sources
- 4
- Term
- Remote code execution (RCE)
- Meaning Here
- A vulnerability that lets an attacker cause code or commands to run on a remote system.2
- Sources
- 2
- Term
- Pre-authentication
| Term | Meaning Here | Sources |
|---|---|---|
| Progress / Kemp / LoadMaster | Progress is the current vendor; Kemp is the legacy product-brand lineage acquired by Progress in 2021; LoadMaster is the application delivery controller and load-balancer product line. The combined name identifies the lineage of one product family, not three separate affected products.11, 12 | 11, 12 |
| Application delivery controller (ADC) | An edge system that distributes and manages application traffic and may terminate TLS, monitor health, switch content, or enforce web-application controls.4 | 4 |
| Remote code execution (RCE) | A vulnerability that lets an attacker cause code or commands to run on a remote system.2 | 2 |
| Pre-authentication | The vulnerable request does not require a valid account before reaching the command-execution path.2, 4, 5 | 2, 4, 5 |
| CISA KEV | A catalog of vulnerabilities CISA has determined are exploited in the wild and that require prioritized federal remediation.1 | 1 |
| Indicator versus evidence | A published IP or request pattern is a hunt lead. Local timing and behavior are required to establish successful exploitation, impact, or attribution.5 | 5 |
- Behavior / ATT&CK
- T1190 — Exploit Public-Facing Application
- Behavior / ATT&CK
- T1059 — Command and Scripting Interpreter
| Behavior / ATT&CK | Campaign Mapping | Sources |
|---|---|---|
| T1190 — Exploit Public-Facing Application | An attacker targets reachable LoadMaster API functionality for initial access.2, 4, 5, 8 | 2, 4, 5, 8 |
| T1059 — Command and Scripting Interpreter | The vulnerability can inject attacker-controlled content into a command executed by the appliance.2, 4, 5, 9 | 2, 4, 5, 9 |
| Post-access discovery — locally unconfirmed | Review for appliance configuration, interface, route, certificate, account, and served-application discovery; these are investigative hypotheses, not behaviors confirmed in eSentire's unsuccessful attempts.5 | 5 |
| Impact and lateral movement — possible, not confirmed | Successful edge-appliance compromise could support disruption or downstream access, but no retained source documents those outcomes for a named victim.2, 5 | 2, 5 |
- Question
- What is LoadMaster?
- Question
- Is exploitation confirmed?
- Question
- Is ransomware using it?
- Question
- Does patching close the incident?
- Question
- Who is exploiting it?
- Question
- What do Progress, Kemp, and LoadMaster mean?
- Question
- Does KEV prove our appliance was compromised?
| Question | Source-bound Answer |
|---|---|
| What is LoadMaster? | A load balancer and application delivery controller that can distribute application traffic, terminate TLS, perform health checks, switch content, and provide web-application-firewall functions.3, 4 |
| Is exploitation confirmed? | Yes at the ecosystem level: CISA added the CVE to KEV. eSentire separately observed exploitation attempts, but reported that its observed attempts were unsuccessful.1, 5 |
| Is ransomware using it? | No retained source establishes ransomware use. Treat ransomware as a plausible post-access outcome requiring defensive readiness, not as a confirmed CVE-2026-8037 relationship.1, 5, 10 |
| Does patching close the incident? | Patching removes the known vulnerable condition. It does not prove that a previously exposed appliance was not accessed; review historical API, appliance, authentication, configuration, and network evidence.1, 3, 5 |
| Who is exploiting it? | No actor is named by CISA, Progress, Canada, eSentire, H-ISAC, or the retained technical research. Do not attribute activity from the CVE or IPs alone.1, 3, 5, 6 |
| What do Progress, Kemp, and LoadMaster mean? | Progress is the vendor, Kemp is the legacy product-brand lineage acquired by Progress, and LoadMaster is the application delivery controller and load-balancer product line.11, 12 |
| Does KEV prove our appliance was compromised? | No. KEV establishes exploitation in the ecosystem. A local conclusion requires evidence from the appliance and surrounding network, HTTP, identity, application and host telemetry.1, 4, 5 |
Use this reference map to answer different vulnerability-management questions from the source that controls each answer. It is a navigation and ownership card, not a duplicate technical summary.
- Reference Question
- Is prioritized known exploitation established?
- Controlling Record
- CISA KEV catalog entry
- How to Use It
- Use for catalog inclusion and federal remediation context. Do not use it to infer the local victim, actor, method or impact.
- Sources
- 11
- Reference Question
- What are the consolidated CVE fields?
- Controlling Record
- NIST NVD CVE-2026-8037 record
- How to Use It
- Use for description, CVSS records, CWE, SSVC and reference links, while recognizing that scoring does not determine deployment reachability.
- Sources
- 22
- Reference Question
- Which product guidance controls remediation?
- Controlling Record
- Progress June 2026 LoadMaster security bulletin
- How to Use It
- Use current vendor scope and branch-specific fixed-build instructions for change approval and validation.
- Sources
- 33
- Reference Question
- Where are mechanism and activity claims sourced?
- Controlling Record
- watchTowr technical analysis and eSentire advisory
- How to Use It
- Use each publisher's own statement for API conditions, proof-of-concept timing, observed attempts, published IPs and unsuccessful-attempt boundary.
| Reference Question | Controlling Record | How to Use It | Sources |
|---|---|---|---|
| Is prioritized known exploitation established? | CISA KEV catalog entry | Use for catalog inclusion and federal remediation context. Do not use it to infer the local victim, actor, method or impact. | 11 |
| What are the consolidated CVE fields? | NIST NVD CVE-2026-8037 record | Use for description, CVSS records, CWE, SSVC and reference links, while recognizing that scoring does not determine deployment reachability. | 22 |
| Which product guidance controls remediation? | Progress June 2026 LoadMaster security bulletin | Use current vendor scope and branch-specific fixed-build instructions for change approval and validation. | 33 |
| Where are mechanism and activity claims sourced? | watchTowr technical analysis and eSentire advisory | Use each publisher's own statement for API conditions, proof-of-concept timing, observed attempts, published IPs and unsuccessful-attempt boundary. | 4, 54, 5 |
The rows separate public attacker infrastructure from behavior-based observables. Categories without reliable issue-specific values are stated explicitly; no indicators are imported from another vulnerability, and product versions are handled in vulnerability and technology-risk cards rather than as IOCs.
- Category
- Attacker IP addresses
- Public Value / Status
- 192.42.116.58; 192.42.116.105; 146.70.139.154
- Detection and Triage Use
- Search historical ingress and egress, firewall, proxy, flow and API telemetry. Correlate timing and request behavior before blocking, escalating or attributing.
- Sources
- eSentire5
- Category
- Attacker domains / FQDNs
- Public Value / Status
- Not public in retained reliable issue-specific sources.
- Detection and Triage Use
- Do not invent, enrich into, or import domains from unrelated infrastructure. Preserve DNS evidence for local investigation.
- Category
- Attacker-controlled or malicious URLs
- Public Value / Status
- Not public in retained reliable issue-specific sources.
- Detection and Triage Use
- The product endpoint below is not an attacker-controlled URL. Preserve full owned HTTP request metadata without publishing exploit payloads.
- Category
- Malware filenames / file names
- Public Value / Status
- Not public and not established as applicable in retained reliable issue-specific sources.
- Detection and Triage Use
- Hunt local file creation only when appliance or surrounding host evidence supports it; do not assign malware names from this CVE alone.
- Sources
- Observed-activity boundary5
- Category
- Malware file hashes / SHA-256
- Public Value / Status
- Not public and not established as applicable in retained reliable issue-specific sources.
- Detection and Triage Use
- No MD5, SHA-1 or SHA-256 value is retained for this issue. Do not substitute proof-of-concept or unrelated malware hashes.
- Sources
- Observed-activity boundary5
- Category
- HTTP observable
- Public Value / Status
- Abnormal requests to /accessv2 when the LoadMaster API is enabled
- Detection and Triage Use
- Review method, source, time, response, session context, request volume and adjacent appliance events; avoid reproducing exploit payloads in routine hunting.
- Category
- Network observable
- Public Value / Status
- Unexpected connections to or from the three published IPs and unusual appliance-originated egress
- Detection and Triage Use
- Correlate flows with API requests, configuration changes and downstream authentication; an address match alone is not proof of success or identity.
- Sources
- eSentire5
- Category
- Product observable
- Public Value / Status
- Unexpected API activity, configuration changes, new administrative objects, certificate access or unexplained appliance errors
- Detection and Triage Use
- Compare with approved change records and known-good configuration; preserve logs before containment or rebuild.
- Category
- Identity observable
- Public Value / Status
- New or modified accounts, keys, tokens or sessions; downstream authentication originating from appliance-adjacent sources
- Detection and Triage Use
- Review administrative and application identity history. These are topic-specific hunt hypotheses, not behaviors confirmed in eSentire's unsuccessful attempts.
- Sources
- Observed-activity boundary5
- Category
- Host / process observable
- Public Value / Status
- Unexpected command or shell execution, child processes, persistence artifacts or file changes on the appliance or managed host
- Detection and Triage Use
- Alert and preserve process and filesystem evidence where telemetry exists. No concrete filename or hash is public for this issue.
- Category
- Application observable
- Public Value / Status
- Unusual command-endpoint errors, exception patterns, response anomalies or service instability near suspicious API requests
- Detection and Triage Use
- Correlate HTTP and appliance logs with health checks, backend application behavior and operator changes.
- Category
- Evidence preservation
- Public Value / Status
- API, web, audit, authentication, configuration, process, DNS, proxy, firewall and network-flow records
- Detection and Triage Use
- Preserve the vulnerable-period window before cleanup so successful access, impact and attribution can be assessed from owned evidence.
| Category | Public Value / Status | Detection and Triage Use | Sources |
|---|---|---|---|
| Attacker IP addresses | 192.42.116.58; 192.42.116.105; 146.70.139.154 | Search historical ingress and egress, firewall, proxy, flow and API telemetry. Correlate timing and request behavior before blocking, escalating or attributing. | eSentire5 |
| Attacker domains / FQDNs | Not public in retained reliable issue-specific sources. | Do not invent, enrich into, or import domains from unrelated infrastructure. Preserve DNS evidence for local investigation. | Retained source boundary1, 3, 5, 6 |
| Attacker-controlled or malicious URLs | Not public in retained reliable issue-specific sources. | The product endpoint below is not an attacker-controlled URL. Preserve full owned HTTP request metadata without publishing exploit payloads. | Technical and observed-activity boundary4, 5 |
| Malware filenames / file names | Not public and not established as applicable in retained reliable issue-specific sources. | Hunt local file creation only when appliance or surrounding host evidence supports it; do not assign malware names from this CVE alone. | Observed-activity boundary5 |
| Malware file hashes / SHA-256 | Not public and not established as applicable in retained reliable issue-specific sources. | No MD5, SHA-1 or SHA-256 value is retained for this issue. Do not substitute proof-of-concept or unrelated malware hashes. | Observed-activity boundary5 |
| HTTP observable | Abnormal requests to /accessv2 when the LoadMaster API is enabled | Review method, source, time, response, session context, request volume and adjacent appliance events; avoid reproducing exploit payloads in routine hunting. | watchTowr and eSentire4, 5 |
| Network observable | Unexpected connections to or from the three published IPs and unusual appliance-originated egress | Correlate flows with API requests, configuration changes and downstream authentication; an address match alone is not proof of success or identity. | eSentire5 |
| Product observable | Unexpected API activity, configuration changes, new administrative objects, certificate access or unexplained appliance errors | Compare with approved change records and known-good configuration; preserve logs before containment or rebuild. | Vendor and technical context3, 4, 5 |
| Identity observable | New or modified accounts, keys, tokens or sessions; downstream authentication originating from appliance-adjacent sources | Review administrative and application identity history. These are topic-specific hunt hypotheses, not behaviors confirmed in eSentire's unsuccessful attempts. | Observed-activity boundary5 |
| Host / process observable | Unexpected command or shell execution, child processes, persistence artifacts or file changes on the appliance or managed host | Alert and preserve process and filesystem evidence where telemetry exists. No concrete filename or hash is public for this issue. | NVD and technical research2, 4, 5 |
| Application observable | Unusual command-endpoint errors, exception patterns, response anomalies or service instability near suspicious API requests | Correlate HTTP and appliance logs with health checks, backend application behavior and operator changes. | Technical research4, 5 |
| Evidence preservation | API, web, audit, authentication, configuration, process, DNS, proxy, firewall and network-flow records | Preserve the vulnerable-period window before cleanup so successful access, impact and attribution can be assessed from owned evidence. | Government and observed-activity guidance1, 5, 6 |
- Actor / Label
- Unattributed exploitation activity
- Actor / Label
- Ransomware — not established
- Actor / Label
- Published IPs are not actor identities
- Attribution Boundary
- The three eSentire-published attacker IP addresses are hunt leads. Shared, rented, relayed or changed infrastructure can serve multiple operators, so an IP match cannot name a person, group or campaign without independent evidence.5
- Sources
- 5
| Actor / Label | Attribution Boundary | Sources |
|---|---|---|
| Unattributed exploitation activity | CISA confirms exploitation and eSentire reports attempts, but no retained authoritative source names the responsible actor or cluster.1, 5 | 1, 5 |
| Ransomware — not established | No retained source links CVE-2026-8037 to a ransomware group, deployment, victim, or claim. Preserve this boundary in reporting.1, 5, 10 | 1, 5, 10 |
| Published IPs are not actor identities | The three eSentire-published attacker IP addresses are hunt leads. Shared, rented, relayed or changed infrastructure can serve multiple operators, so an IP match cannot name a person, group or campaign without independent evidence.5 | 5 |
- Audience
- Executive
- Audience
- SOC / IR
- Audience
- Insurance / claims
- Audience
- Asset and communications
| Audience | Decision-ready Point | Sources |
|---|---|---|
| Executive | This is a known-exploited, unauthenticated edge-appliance RCE. We need both fixed-version proof and a historical exposure conclusion.1, 2, 3 | 1, 2, 3 |
| SOC / IR | Hunt the three IPs and /accessv2 activity, but require behavioral and temporal corroboration before declaring compromise or attribution.4, 5 | 4, 5 |
| Insurance / claims | Edge compromise and downtime are material portfolio concerns; the retained record does not support a LoadMaster-specific ransomware claim.5, 10 | 5, 10 |
| Asset and communications | Progress is the vendor, Kemp is the legacy product-brand lineage, and LoadMaster is the ADC and load-balancer product line. Use the combined name to find assets without describing three separate products.11, 12 | 11, 12 |
| MSP / customer success | A shared appliance or management path can concentrate trust, but customer impact must be scoped tenant by tenant from routing, credentials, evidence and contractual relationships.2, 3, 4, 5 | 2, 3, 4, 5 |
These are management decisions and completion criteria, distinct from the evidence-preservation and technical workflow in the incident-response card.
- Decision
- Assign accountable owner
- Trigger / Required Evidence
- Any LoadMaster or related affected Progress ADC product exists or historical presence is uncertain.
- Completion Standard
- Named business and technical owners attest to inventory, API state, served applications and remediation status.
- Decision
- Authorize emergency change
- Trigger / Required Evidence
- Affected branch/build with enabled or potentially reachable API functionality.
- Completion Standard
- Correct fixed build is verified and unnecessary reachability is removed without losing required evidence.
- Decision
- Open or escalate incident
- Trigger / Required Evidence
- IOC match plus corroborating suspicious request, command, configuration, identity, process or downstream behavior.
- Completion Standard
- Scope, timeline, affected trust paths, evidence gaps and impact conclusion are documented.
- Decision
- Rotate reachable trust
- Trigger / Required Evidence
- Evidence or unresolved uncertainty shows credentials, keys or certificates could have been accessed.
- Completion Standard
- Prioritized secrets and certificates are replaced, dependents are validated and old material is revoked.
- Decision
- Notify stakeholders
- Trigger / Required Evidence
- Confirmed access or impact meets contractual, legal, insurance or customer thresholds.
- Completion Standard
- Notices distinguish confirmed facts from uncertainty and avoid unsupported actor or ransomware claims.
| Decision | Trigger / Required Evidence | Completion Standard | Sources |
|---|---|---|---|
| Assign accountable owner | Any LoadMaster or related affected Progress ADC product exists or historical presence is uncertain. | Named business and technical owners attest to inventory, API state, served applications and remediation status. | 2, 3, 62, 3, 6 |
| Authorize emergency change | Affected branch/build with enabled or potentially reachable API functionality. | Correct fixed build is verified and unnecessary reachability is removed without losing required evidence. | 1, 3, 51, 3, 5 |
| Open or escalate incident | IOC match plus corroborating suspicious request, command, configuration, identity, process or downstream behavior. | Scope, timeline, affected trust paths, evidence gaps and impact conclusion are documented. | 4, 54, 5 |
| Rotate reachable trust | Evidence or unresolved uncertainty shows credentials, keys or certificates could have been accessed. | Prioritized secrets and certificates are replaced, dependents are validated and old material is revoked. | 2, 4, 52, 4, 5 |
| Notify stakeholders | Confirmed access or impact meets contractual, legal, insurance or customer thresholds. | Notices distinguish confirmed facts from uncertainty and avoid unsupported actor or ransomware claims. | 1, 5, 101, 5, 10 |
- Technology / Trust Path
- Enabled API exposed to untrusted networks
- Technology / Trust Path
- Concentrated edge trust
- Technology / Trust Path
- Mixed GA and LTSF branches
| Technology / Trust Path | Risk / Defensive Priority | Sources |
|---|---|---|
| Enabled API exposed to untrusted networks | The documented RCE path requires reachable vulnerable API functionality. Restrict reachability and remove unnecessary exposure.3, 4, 5 | 3, 4, 5 |
| Concentrated edge trust | LoadMaster can broker traffic for multiple critical applications, making compromise operationally significant even without endpoint-scale deployment.4, 5 | 4, 5 |
| Mixed GA and LTSF branches | Different fixed versions create patch-verification risk. Record the branch and exact running build rather than accepting a generic 'updated' statement.3, 5, 6 | 3, 5, 6 |
| Insufficient appliance telemetry | Missing historical logs can prevent a defensible compromise conclusion; document the gap and use surrounding network, identity, and application evidence.1, 5 | 1, 5 |
Each tier is shown separately. A zero-retention row means the tier was checked but did not add decision-grade, topic-specific evidence; it does not imply that material was unavailable on the wider web.
- Tier
- Tier 0
- Retained Sources / Result
- CISA, NVD, Progress, Canadian Centre for Cyber Security
- Use and Evidence Boundary
- Controls KEV status, consolidated vulnerability fields, vendor terminology, product scope, affected and fixed builds, and government advisory context.
- Tier
- Tier 1
- Retained Sources / Result
- watchTowr Labs and eSentire TRU
- Use and Evidence Boundary
- Supports technical mechanism, public proof-of-concept timing, observed-attempt reporting, concrete IPs and the explicit unsuccessful-attempt boundary.
- Tier
- Tier 2
- Retained Sources / Result
- H-ISAC / AHA and At-Bay
- Use and Evidence Boundary
- Adds sector amplification and portfolio-level SMB, remote-access and interruption context; it does not establish local compromise or LoadMaster-specific ransomware causation.
- Tier
- Tier 3
- Retained Sources / Result
- No additional source retained
- Use and Evidence Boundary
- Established security reporting was checked but did not supersede or materially extend the primary and original-research record for this terminology-only update.
- Sources
- Source-review result
- Tier
- Tier 4
- Retained Sources / Result
- No additional source retained
- Use and Evidence Boundary
- Community and practitioner reporting was treated as lead generation only and did not add reliable issue-specific evidence needed for this update.
- Sources
- Source-review result
- Tier
- Tier 5
- Retained Sources / Result
- MITRE ATT&CK
- Use and Evidence Boundary
- Provides behavior taxonomy for exploitation of public-facing applications and command execution; it does not confirm that a behavior occurred in a named victim environment.
- Tier
- Tier 6
- Retained Sources / Result
- No social or forum source retained
- Use and Evidence Boundary
- Social posts were not used to change exploitation, attribution, victim, indicator or impact claims.
- Sources
- Source-review result
- Tier
- Tier 7
- Retained Sources / Result
- No aggregator or search-only source retained
- Use and Evidence Boundary
- Search snippets and aggregations were used only to discover primary pages and were not cited as controlling evidence.
- Sources
- Source-review result
- Tier
- Tier 8
- Retained Sources / Result
- No unverified source retained
- Use and Evidence Boundary
- Unsupported claims, copied indicators and unrelated vulnerability material were excluded from the candidate.
- Sources
- Exclusion boundary
| Tier | Retained Sources / Result | Use and Evidence Boundary | Sources |
|---|---|---|---|
| Tier 0 | CISA, NVD, Progress, Canadian Centre for Cyber Security | Controls KEV status, consolidated vulnerability fields, vendor terminology, product scope, affected and fixed builds, and government advisory context. | 1, 2, 3, 6, 11, 121, 2, 3, 6, 11, 12 |
| Tier 1 | watchTowr Labs and eSentire TRU | Supports technical mechanism, public proof-of-concept timing, observed-attempt reporting, concrete IPs and the explicit unsuccessful-attempt boundary. | 4, 54, 5 |
| Tier 2 | H-ISAC / AHA and At-Bay | Adds sector amplification and portfolio-level SMB, remote-access and interruption context; it does not establish local compromise or LoadMaster-specific ransomware causation. | 7, 107, 10 |
| Tier 3 | No additional source retained | Established security reporting was checked but did not supersede or materially extend the primary and original-research record for this terminology-only update. | Source-review result |
| Tier 4 | No additional source retained | Community and practitioner reporting was treated as lead generation only and did not add reliable issue-specific evidence needed for this update. | Source-review result |
| Tier 5 | MITRE ATT&CK | Provides behavior taxonomy for exploitation of public-facing applications and command execution; it does not confirm that a behavior occurred in a named victim environment. | 8, 98, 9 |
| Tier 6 | No social or forum source retained | Social posts were not used to change exploitation, attribution, victim, indicator or impact claims. | Source-review result |
| Tier 7 | No aggregator or search-only source retained | Search snippets and aggregations were used only to discover primary pages and were not cited as controlling evidence. | Source-review result |
| Tier 8 | No unverified source retained | Unsupported claims, copied indicators and unrelated vulnerability material were excluded from the candidate. | Exclusion boundary |
- Issue
- 9.6 versus 9.8 CVSS
- How IntelliOS Handles It
- Progress's CNA score is 9.6 with adjacent-network reach; NVD displays a 9.8 network-reachable assessment. Both rate the issue Critical. Exposure must be decided from actual API reachability.2
- Sources
- 2
- Issue
- Attempts versus successful exploitation
- Issue
- Product version scope
- Issue
- Insurance context versus causation
- How IntelliOS Handles It
- At-Bay's ransomware statistics show why edge and downtime controls matter. They do not identify LoadMaster, this CVE, or the three published IPs as claim causes.10
- Sources
- 10
- Issue
- Vendor, legacy brand, and product line
| Issue | How IntelliOS Handles It | Sources |
|---|---|---|
| 9.6 versus 9.8 CVSS | Progress's CNA score is 9.6 with adjacent-network reach; NVD displays a 9.8 network-reachable assessment. Both rate the issue Critical. Exposure must be decided from actual API reachability.2 | 2 |
| Attempts versus successful exploitation | CISA KEV confirms exploitation somewhere in the ecosystem. eSentire reports that the attempts it observed were unsuccessful. Those statements are compatible and must not be collapsed into a victim claim.1, 5 | 1, 5 |
| Product version scope | Progress/NVD cover LoadMaster and related ADC products; Canada summarizes GA 7.2.63.1 and prior and LTSF 7.2.54.17 and prior. Use current vendor guidance for exact product applicability.2, 3, 6 | 2, 3, 6 |
| Insurance context versus causation | At-Bay's ransomware statistics show why edge and downtime controls matter. They do not identify LoadMaster, this CVE, or the three published IPs as claim causes.10 | 10 |
| Vendor, legacy brand, and product line | Progress's acquisition and product records support a narrow naming clarification: Progress is the vendor, Kemp is the acquired legacy brand lineage, and LoadMaster is the ADC and load-balancer line. This terminology does not change any security finding.11, 12 | 11, 12 |
These are external source organizations, not authorship credits. Each row states what the organization does, why it matters to this topic, and the limit of the evidence used.
- External Organization
- CISA
- What They Do
- U.S. civilian cybersecurity agency that maintains the Known Exploited Vulnerabilities catalog.
- Why They Matter Here
- Its catalog entry controls the brief's known-exploitation status and federal remediation deadline context.
- Evidence Boundary
- KEV does not identify the actor, victim count, exploitation method in each incident or local impact.
- Sources
- 11
- External Organization
- Progress Software
- What They Do
- Vendor that acquired Kemp and publishes LoadMaster product information and security guidance.
- Why They Matter Here
- It controls the Progress–Kemp–LoadMaster terminology, product scope and fixed-version guidance.
- Evidence Boundary
- Vendor material does not establish compromise of a particular customer or actor attribution.
- External Organization
- NIST NVD
- What They Do
- U.S. government vulnerability database that consolidates CVE metadata, scoring and references.
- Why They Matter Here
- It supplies the consolidated description, CVSS records, CWE and affected-product references.
- Evidence Boundary
- A database record does not prove internet exposure, exploit success or impact in a specific environment.
- Sources
- 22
- External Organization
- watchTowr Labs
- What They Do
- Independent security research organization focused on original vulnerability analysis and attack-surface research.
- Why They Matter Here
- Its work explains the API-related technical path and public proof-of-concept timeline.
- Evidence Boundary
- Research and a proof of concept demonstrate feasibility, not compromise of a named organization.
- Sources
- 44
- External Organization
- eSentire Threat Response Unit
- What They Do
- Managed detection and response provider with a threat research and advisory function.
- Why They Matter Here
- It reported observed attempts, three attacker IPs, /accessv2 context and the fact that its observed attempts were unsuccessful.
- Evidence Boundary
- Its telemetry statement applies to what it observed and does not identify a universal actor or prove other victims were compromised.
- Sources
- 55
- External Organization
- Canadian Centre for Cyber Security
- What They Do
- Canada's national technical authority for cybersecurity alerts and advice.
- Why They Matter Here
- It corroborates affected versions and the August 7 KEV update.
- Evidence Boundary
- Its advisory is corroboration, not a public victim report or attribution finding.
- Sources
- 66
- External Organization
- H-ISAC / American Hospital Association
- What They Do
- Health-sector information-sharing and industry coordination organizations.
- Why They Matter Here
- They amplified the observed-attempt warning and patch priority for healthcare defenders.
- Evidence Boundary
- The retained notice does not establish a named healthcare victim or successful exploitation.
- Sources
- 77
- External Organization
- At-Bay
- What They Do
- Cyber-insurance provider that publishes portfolio loss and security-control research.
- Why They Matter Here
- Its data supplies SMB, remote-access and business-interruption context for risk decisions.
- Evidence Boundary
- Portfolio statistics do not connect LoadMaster, this CVE, an actor or the published IPs to ransomware claims.
- Sources
- 1010
| External Organization | What They Do | Why They Matter Here | Evidence Boundary | Sources |
|---|---|---|---|---|
| CISA | U.S. civilian cybersecurity agency that maintains the Known Exploited Vulnerabilities catalog. | Its catalog entry controls the brief's known-exploitation status and federal remediation deadline context. | KEV does not identify the actor, victim count, exploitation method in each incident or local impact. | 11 |
| Progress Software | Vendor that acquired Kemp and publishes LoadMaster product information and security guidance. | It controls the Progress–Kemp–LoadMaster terminology, product scope and fixed-version guidance. | Vendor material does not establish compromise of a particular customer or actor attribution. | 3, 11, 123, 11, 12 |
| NIST NVD | U.S. government vulnerability database that consolidates CVE metadata, scoring and references. | It supplies the consolidated description, CVSS records, CWE and affected-product references. | A database record does not prove internet exposure, exploit success or impact in a specific environment. | 22 |
| watchTowr Labs | Independent security research organization focused on original vulnerability analysis and attack-surface research. | Its work explains the API-related technical path and public proof-of-concept timeline. | Research and a proof of concept demonstrate feasibility, not compromise of a named organization. | 44 |
| eSentire Threat Response Unit | Managed detection and response provider with a threat research and advisory function. | It reported observed attempts, three attacker IPs, /accessv2 context and the fact that its observed attempts were unsuccessful. | Its telemetry statement applies to what it observed and does not identify a universal actor or prove other victims were compromised. | 55 |
| Canadian Centre for Cyber Security | Canada's national technical authority for cybersecurity alerts and advice. | It corroborates affected versions and the August 7 KEV update. | Its advisory is corroboration, not a public victim report or attribution finding. | 66 |
| H-ISAC / American Hospital Association | Health-sector information-sharing and industry coordination organizations. | They amplified the observed-attempt warning and patch priority for healthcare defenders. | The retained notice does not establish a named healthcare victim or successful exploitation. | 77 |
| At-Bay | Cyber-insurance provider that publishes portfolio loss and security-control research. | Its data supplies SMB, remote-access and business-interruption context for risk decisions. | Portfolio statistics do not connect LoadMaster, this CVE, an actor or the published IPs to ransomware claims. | 1010 |
- Example
- No publicly named victim retained
- Example
- eSentire-observed attempts
- What It Shows / Boundary
- The provider observed attempts but states they were unsuccessful; this is not a public-victim record.5
- Sources
- 5
| Example | What It Shows / Boundary | Sources |
|---|---|---|
| No publicly named victim retained | The retained government, vendor, and research sources do not identify a successfully compromised organization by name.1, 3, 5, 6 | 1, 3, 5, 6 |
| eSentire-observed attempts | The provider observed attempts but states they were unsuccessful; this is not a public-victim record.5 | 5 |
| CISA KEV ecosystem finding | KEV establishes known exploitation, not the identity, count, sector, or impact of victims.1 | 1 |
| Local disclosure decision | An organization should base customer, insurer, legal or regulatory disclosure on confirmed access, affected trust, data, service and contractual facts from its own investigation—not on product ownership or KEV status alone.1, 5, 10 | 1, 5, 10 |
Only explicitly public vendor or organization disclosures belong here. The rows below describe the public record and do not represent an affected-party list.
- Disclosure / Affected Set
- No publicly named victim retained
- Disclosure / Affected Set
- eSentire-observed attempts
- Disclosure Boundary
- The provider observed attempts but states they were unsuccessful; this is not a public-victim record.5
- Sources
- 5
- Disclosure / Affected Set
- CISA KEV ecosystem finding
- Disclosure Boundary
- KEV establishes known exploitation, not the identity, count, sector, or impact of victims.1
- Sources
- 1
- Disclosure / Affected Set
- Local disclosure decision
| Disclosure / Affected Set | Disclosure Boundary | Sources |
|---|---|---|
| No publicly named victim retained | The retained government, vendor, and research sources do not identify a successfully compromised organization by name.1, 3, 5, 6 | 1, 3, 5, 6 |
| eSentire-observed attempts | The provider observed attempts but states they were unsuccessful; this is not a public-victim record.5 | 5 |
| CISA KEV ecosystem finding | KEV establishes known exploitation, not the identity, count, sector, or impact of victims.1 | 1 |
| Local disclosure decision | An organization should base customer, insurer, legal or regulatory disclosure on confirmed access, affected trust, data, service and contractual facts from its own investigation—not on product ownership or KEV status alone.1, 5, 10 | 1, 5, 10 |
- Item
- CVE-2026-8037
- Item
- CVE-2026-33691
- Status / Meaning
- Companion vulnerability in the same Progress June bulletin. It is retained for full-bulletin patch review but is not silently treated as the exploitation path described for CVE-2026-8037.3
- Sources
- 3
- Item
- CWE and scoring interpretation
- Status / Meaning
- NVD records OS command injection and displays Critical CVSS v3.1 assessments, including 9.8 from NVD and 9.6 from Progress. Scores prioritize severity but do not prove API reachability, exploitation success or local impact.2
- Sources
- 2
- Item
- Technical precondition and fix boundary
| Item | Status / Meaning | Sources |
|---|---|---|
| CVE-2026-8037 | Critical unauthenticated OS command-injection RCE in affected Progress ADC products. GA fixed in 7.2.63.2; LTSF fixed in 7.2.54.18. Added to CISA KEV Aug 7, 2026.1, 2, 3, 5, 6 | 1, 2, 3, 5, 6 |
| CVE-2026-33691 | Companion vulnerability in the same Progress June bulletin. It is retained for full-bulletin patch review but is not silently treated as the exploitation path described for CVE-2026-8037.3 | 3 |
| CWE and scoring interpretation | NVD records OS command injection and displays Critical CVSS v3.1 assessments, including 9.8 from NVD and 9.6 from Progress. Scores prioritize severity but do not prove API reachability, exploitation success or local impact.2 | 2 |
| Technical precondition and fix boundary | The retained technical path requires affected API functionality to be enabled and reachable. Verify GA 7.2.63.2 or later or LTSF 7.2.54.18 or later against current Progress guidance; patching does not answer whether prior access occurred.2, 3, 4, 5, 6 | 2, 3, 4, 5, 6 |
This lifecycle view separates the one source-supported access-and-execution sequence from later investigative hypotheses. ATT&CK provides vocabulary; owned evidence decides whether any phase occurred.
- Lifecycle Phase
- Initial access
- Public Evidence Status
- T1190 is a defensible taxonomy for targeting reachable public-facing API functionality.
- What Defenders Must Validate
- Establish interface and source-network reachability, request timing, endpoint activity, response outcome and appliance events. A scan or request does not by itself prove code execution.
- Lifecycle Phase
- Execution
- Public Evidence Status
- T1059 describes the command-execution consequence of successful injection.
- What Defenders Must Validate
- Look for shell or command processes, child activity, system errors, file or configuration effects and correlated egress. eSentire said the attempts it observed were unsuccessful.
- Lifecycle Phase
- Persistence and credential access
- Public Evidence Status
- Not confirmed in the retained public record for a named victim.
- What Defenders Must Validate
- Review administrative objects, keys, certificates, tokens, scheduled or startup artifacts and changes against known-good state. Treat findings as local evidence, not assumed campaign behavior.
- Lifecycle Phase
- Discovery, lateral movement and impact
- Public Evidence Status
- Plausible after appliance compromise but not documented as an issue-specific public victim sequence.
- What Defenders Must Validate
- Examine served applications, routes, tenants, downstream authentication, data access and service interruption. Report only phases supported by owned telemetry and forensic analysis.
| Lifecycle Phase | Public Evidence Status | What Defenders Must Validate | Sources |
|---|---|---|---|
| Initial access | T1190 is a defensible taxonomy for targeting reachable public-facing API functionality. | Establish interface and source-network reachability, request timing, endpoint activity, response outcome and appliance events. A scan or request does not by itself prove code execution. | 2, 4, 5, 82, 4, 5, 8 |
| Execution | T1059 describes the command-execution consequence of successful injection. | Look for shell or command processes, child activity, system errors, file or configuration effects and correlated egress. eSentire said the attempts it observed were unsuccessful. | 2, 4, 5, 92, 4, 5, 9 |
| Persistence and credential access | Not confirmed in the retained public record for a named victim. | Review administrative objects, keys, certificates, tokens, scheduled or startup artifacts and changes against known-good state. Treat findings as local evidence, not assumed campaign behavior. | 3, 53, 5 |
| Discovery, lateral movement and impact | Plausible after appliance compromise but not documented as an issue-specific public victim sequence. | Examine served applications, routes, tenants, downstream authentication, data access and service interruption. Report only phases supported by owned telemetry and forensic analysis. | 1, 2, 51, 2, 5 |
Source weight follows the claim being made. Primary sources control official status and product facts; original research controls what it observed or demonstrated; contextual sources cannot be promoted into incident evidence.
- Source Class
- CISA and national advisories
- Controlling Use
- Highest for KEV status, federal action and government advisory chronology.
- Relevance Limit
- Do not infer a local victim, actor, successful technique or business impact from catalog inclusion.
- Source Class
- Progress vendor records
- Controlling Use
- Highest for vendor identity, Kemp lineage, LoadMaster product description, affected scope and fixed builds.
- Relevance Limit
- Vendor records do not establish exploitation success or impact at a customer.
- Source Class
- NIST NVD
- Controlling Use
- High for consolidated CVE description, CVSS records, CWE, product references and linked authorities.
- Relevance Limit
- Scoring and metadata do not substitute for actual reachability or forensic evidence.
- Citations
- 22
- Source Class
- watchTowr and eSentire
- Controlling Use
- High for technical feasibility, proof-of-concept timing, observed attempts, endpoint context and published IPs.
- Relevance Limit
- Each organization controls only its own research and observations; eSentire explicitly reported unsuccessful attempts.
- Source Class
- H-ISAC / AHA, MITRE and At-Bay
- Controlling Use
- Supporting for sector urgency, behavioral taxonomy and portfolio-level SMB loss context.
- Relevance Limit
- These sources do not establish a LoadMaster victim, actor, ransomware relationship or local compromise.
| Source Class | Controlling Use | Relevance Limit | Citations |
|---|---|---|---|
| CISA and national advisories | Highest for KEV status, federal action and government advisory chronology. | Do not infer a local victim, actor, successful technique or business impact from catalog inclusion. | 1, 61, 6 |
| Progress vendor records | Highest for vendor identity, Kemp lineage, LoadMaster product description, affected scope and fixed builds. | Vendor records do not establish exploitation success or impact at a customer. | 3, 11, 123, 11, 12 |
| NIST NVD | High for consolidated CVE description, CVSS records, CWE, product references and linked authorities. | Scoring and metadata do not substitute for actual reachability or forensic evidence. | 22 |
| watchTowr and eSentire | High for technical feasibility, proof-of-concept timing, observed attempts, endpoint context and published IPs. | Each organization controls only its own research and observations; eSentire explicitly reported unsuccessful attempts. | 4, 54, 5 |
| H-ISAC / AHA, MITRE and At-Bay | Supporting for sector urgency, behavioral taxonomy and portfolio-level SMB loss context. | These sources do not establish a LoadMaster victim, actor, ransomware relationship or local compromise. | 7–107, 8, 9, 10 |
CVE / KEV CARD
Progress Kemp LoadMaster Edge RCE
Canonical vulnerability card; reconcile KEV status and fixed-version fields with this brief.
Rolling Intelligence Card
Government Cybersecurity Actions & Advisories
Tracks CISA KEV additions and government advisory actions.
Rolling Intelligence Card
Cyber Insurance Claims, Coverage & Underwriting
Historical insurance portfolio context for remote access, ransomware, and business interruption.
Rolling Intelligence Card
Exploitable Technology Risk
Tracks high-consequence exposed technology relevant to U.S. SMBs.
Published research notes
Public, read-only, source-backed context retained with this brief. No account or sign-in is required.
Evidence synthesis
Confirmed: critical unauthenticated RCE; fixed builds; public PoC; observed exploitation attempts; three published attacker IPs; CISA KEV addition. Not confirmed: successful compromise in eSentire's cases, named actor, named victim, ransomware use, data theft, or downstream impact.1, 2, 3, 4, 5, 6
IOC handling
Retain only 192.42.116.58, 192.42.116.105, 146.70.139.154, /accessv2, and affected-build fingerprints as concrete public observables. Do not add domains, hashes, filenames, or malware labels without a source tied to this activity.5
Version table
LoadMaster GA: 7.2.63.1 and prior affected, 7.2.63.2 fixed. LoadMaster LTSF: 7.2.54.17 and prior affected, 7.2.54.18 fixed. NVD also lists ECS Connection Manager, ObjectScale Connection Manager, and MOVEit WAF applicability; validate those products against the current Progress bulletin.2, 3, 5, 6
Exploitation language
Use two separate sentences: CISA lists the CVE in KEV, establishing known exploitation; eSentire observed attempts beginning June 29 and reports that its observed attempts were unsuccessful. Never rewrite this as eSentire-confirmed compromise.1, 5
Insurance context table
At-Bay 2025 portfolio findings: VPNs initiated 73% of ransomware claims; VPN plus RDP initiated 87%; ransomware with business interruption was three times more severe; organizations below $25M revenue saw ransomware frequency increase 21% and severity increase 40% to $422K; Akira represented more than 40% of ransomware claims and SonicWall was present in 86% of Akira events. These are historical carrier observations about remote-access and appliance risk. They do not connect LoadMaster, CVE-2026-8037, the published IPs, or any actor to ransomware.10
Rolling Intelligence Card reconciliation
The Government Cybersecurity Rolling Intelligence Card supplies the Aug 7 KEV trigger; Cyber Insurance Rolling Intelligence supplies portfolio context. The CVE card's KEV status should read Known Exploited, while actor, victim, and ransomware fields remain unknown unless new evidence is retained.1, 10
- #
- 1
- Tier
- Tier 0 — U.S. government
- Publisher
- CISA
- Published
- August 7, 2026
- Why Used
- Controls KEV inclusion, known-exploitation status, and required federal action.
- #
- 2
- Tier
- Tier 0 — Government vulnerability record
- Publisher
- NIST NVD
- Published
- June 4, 2026; maintained record
- Why Used
- Controls consolidated description, CVSS records, affected products, CWE, SSVC, and references.
- Source
- CVE-2026-8037
- #
- 3
- Tier
- Tier 0 — Vendor advisory
- Publisher
- Progress Software
- Published
- June 2026
- Why Used
- Controls vendor product scope, fixed builds, and companion-bulletin context.
- #
- 4
- Tier
- Tier 1 — Original technical research
- Publisher
- watchTowr Labs
- Published
- June 29, 2026
- Why Used
- Technical mechanism, API-enabled exposure condition, affected builds, and public PoC timeline.
- #
- 5
- Tier
- Tier 1 — Observed threat activity
- Publisher
- eSentire Threat Response Unit
- Published
- June 30, 2026
- Why Used
- Observed attempts, unsuccessful-attempt boundary, fixed versions, /accessv2, concrete IPs, and operational guidance.
- #
- 6
- Tier
- Tier 0 — Canadian government
- Publisher
- Canadian Centre for Cyber Security
- Published
- June 5, 2026; updated August 7, 2026
- Why Used
- Corroborates affected versions, in-the-wild reporting, and CISA KEV addition.
- #
- 7
- Tier
- Tier 1 — Sector sharing
- Publisher
- H-ISAC / American Hospital Association
- Published
- July 1, 2026
- Why Used
- Sector amplification and patch-priority corroboration.
- #
- 8
- Tier
- Tier 5 — Framework
- Publisher
- MITRE ATT&CK
- Published
- Maintained framework
- Why Used
- Behavioral taxonomy for exploitation of reachable application infrastructure.
- #
- 9
- Tier
- Tier 5 — Framework
- Publisher
- MITRE ATT&CK
- Published
- Maintained framework
- Why Used
- Behavioral taxonomy for command execution.
- #
- 10
- Tier
- Tier 2 — Insurance portfolio context
- Publisher
- At-Bay
- Published
- April 22, 2026
- Why Used
- Historical portfolio context for remote access, SMB ransomware severity, downtime, and strict non-causation boundaries.
- #
- 11
- Tier
- Tier 0 — Vendor corporate record
- Publisher
- Progress Software
- Published
- November 1, 2021
- Why Used
- Primary vendor record establishing that Progress acquired Kemp and supporting the legacy brand-lineage clarification.
- #
- 12
- Tier
- Tier 0 — Vendor product description
- Publisher
- Progress Software
- Published
- Maintained product page; accessed August 9, 2026
- Why Used
- Primary vendor product description identifying Progress Kemp LoadMaster as an application delivery controller and load balancer.
| # | Tier | Publisher | Published | Why Used | Source |
|---|---|---|---|---|---|
| 1 | Tier 0 — U.S. government | CISA | August 7, 2026 | Controls KEV inclusion, known-exploitation status, and required federal action. | Known Exploited Vulnerabilities Catalog — CVE-2026-8037 |
| 2 | Tier 0 — Government vulnerability record | NIST NVD | June 4, 2026; maintained record | Controls consolidated description, CVSS records, affected products, CWE, SSVC, and references. | CVE-2026-8037 |
| 3 | Tier 0 — Vendor advisory | Progress Software | June 2026 | Controls vendor product scope, fixed builds, and companion-bulletin context. | LoadMaster Critical Security Bulletin — June 2026 |
| 4 | Tier 1 — Original technical research | watchTowr Labs | June 29, 2026 | Technical mechanism, API-enabled exposure condition, affected builds, and public PoC timeline. | Enterprise Tech In, Shell Out — CVE-2026-8037 |
| 5 | Tier 1 — Observed threat activity | eSentire Threat Response Unit | June 30, 2026 | Observed attempts, unsuccessful-attempt boundary, fixed versions, /accessv2, concrete IPs, and operational guidance. | Progress Kemp LoadMaster Vulnerability Targeted |
| 6 | Tier 0 — Canadian government | Canadian Centre for Cyber Security | June 5, 2026; updated August 7, 2026 | Corroborates affected versions, in-the-wild reporting, and CISA KEV addition. | Progress security advisory AV26-552 — Update 2 |
| 7 | Tier 1 — Sector sharing | H-ISAC / American Hospital Association | July 1, 2026 | Sector amplification and patch-priority corroboration. | Observed Exploitation Attempts Targeting Critical Progress Kemp LoadMaster Vulnerability |
| 8 | Tier 5 — Framework | MITRE ATT&CK | Maintained framework | Behavioral taxonomy for exploitation of reachable application infrastructure. | T1190 — Exploit Public-Facing Application |
| 9 | Tier 5 — Framework | MITRE ATT&CK | Maintained framework | Behavioral taxonomy for command execution. | T1059 — Command and Scripting Interpreter |
| 10 | Tier 2 — Insurance portfolio context | At-Bay | April 22, 2026 | Historical portfolio context for remote access, SMB ransomware severity, downtime, and strict non-causation boundaries. | 2026 InsurSec Report — Ransomware and VPN Attack Trends |
| 11 | Tier 0 — Vendor corporate record | Progress Software | November 1, 2021 | Primary vendor record establishing that Progress acquired Kemp and supporting the legacy brand-lineage clarification. | Progress Completes Acquisition of Kemp |
| 12 | Tier 0 — Vendor product description | Progress Software | Maintained product page; accessed August 9, 2026 | Primary vendor product description identifying Progress Kemp LoadMaster as an application delivery controller and load balancer. | Progress Federal Solutions — Kemp LoadMaster |
- Version
- v1.1
- Date
- Aug 9, 2026
- Changes
- Terminology clarification only: defined Progress as the vendor, Kemp as the legacy product-brand lineage acquired by Progress, and LoadMaster as the application delivery controller and load-balancer product line. No exploitation, attribution, indicator, severity, affected-version, fixed-version, or impact claim changed.
- Version
- v1.0
- Date
- Aug 8, 2026
- Changes
- Initial source-backed 32-card PANDA Flash Threat Intel Brief. Added KEV reconciliation, affected and fixed versions, exploitation-attempt reporting, concrete IP observables, SMB and insurance context, response actions, attribution limits, public notes, citations, and linked IntelliOS cards.
| Version | Date | Changes |
|---|---|---|
| v1.1 | Aug 9, 2026 | Terminology clarification only: defined Progress as the vendor, Kemp as the legacy product-brand lineage acquired by Progress, and LoadMaster as the application delivery controller and load-balancer product line. No exploitation, attribution, indicator, severity, affected-version, fixed-version, or impact claim changed. |
| v1.0 | Aug 8, 2026 | Initial source-backed 32-card PANDA Flash Threat Intel Brief. Added KEV reconciliation, affected and fixed versions, exploitation-attempt reporting, concrete IP observables, SMB and insurance context, response actions, attribution limits, public notes, citations, and linked IntelliOS cards. |
