CiberLATAMbywhalemate

CVE-2026-8037 lands in CISA's KEV catalog

CISA confirmed exploitation of CVE-2026-8037 in Progress LoadMaster and ECS Connections Manager. Progress published fixed versions.

Whalemate Labs · AI-assisted researchPublished:2 min read

CVE-2026-8037 was added to CISA's Known Exploited Vulnerabilities catalog with confirmed exploitation and a first observed date of August 7, 2026. The issue affects Progress LoadMaster and Progress ECS Connections Manager, while Progress updated its AV26-552 advisory and listed fixed versions for LoadMaster.

CISA confirms active exploitation

CVE-2026-8037 was added to CISA's Known Exploited Vulnerabilities catalog with a confirmed exploitation status. The entry, reflected by CISA and CIRCL, lists August 7, 2026 as the first observed date and places the impact on Progress LoadMaster and Progress ECS Connections Manager.

The same CIRCL CVE database also notes that CVE-2026-63077 was added to KEV with confirmed exploitation and affects JetBrains TeamCity, while CVE-2026-20316 appears in the catalog with the same status for Cisco Secure Firewall Management Center. Together, the three entries show CISA continuing to add flaws that have already been exploited in products widely used in enterprise environments.

What Progress said

Progress published an update to its AV26-552 security advisory and said that, in the case of CVE-2026-8037, the public report points to in-the-wild exploitation. In that same update, the company said CISA added the vulnerability to KEV on August 7, 2026.

According to the documentation released by Progress, the flaw affects LoadMaster GA v7.2.63.1 and earlier, and LoadMaster LTSF v7.2.54.17 and earlier. The fixed versions published were GA v7.2.63.2 and LTSF v7.2.54.18.

AltonaSpain also reported that exploitation attempts against this critical vulnerability in Progress Kemp LoadMaster have already been detected, in line with Progress's update and the CVE's addition to the KEV catalog.

KEV catalog context

CISA's KEV catalog, as reflected by CIRCL, marks CVE-2026-8037 as confirmed, exploited, and first observed on August 7, 2026. The entry lists Progress LoadMaster and Progress ECS Connections Manager as affected, two infrastructure products that often move to the center of alerts when actively exploited flaws surface.

The overlap between Progress's advisory, the KEV listing, and the technical coverage published by AltonaSpain leaves CVE-2026-8037 as the latest case in the reviewed material to show confirmed exploitation in a widely deployed traffic balancing and security product.

Sources

View all