CVE-2026-8037 lands in CISA's KEV catalog
CISA confirmed exploitation of CVE-2026-8037 in Progress LoadMaster and ECS Connections Manager. Progress published fixed versions.
CVE-2026-8037 was added to CISA's Known Exploited Vulnerabilities catalog with confirmed exploitation and a first observed date of August 7, 2026. The issue affects Progress LoadMaster and Progress ECS Connections Manager, while Progress updated its AV26-552 advisory and listed fixed versions for LoadMaster.
CVE-2026-8037 was added to CISA’s Known Exploited Vulnerabilities catalog as a confirmed exploited issue, with a first observed date of Aug. 7, 2026, according to CISA and CIRCL. The vulnerability affects Progress LoadMaster and Progress ECS Connections Manager. Progress released fixed versions for LoadMaster GA v7.2.63.1 and earlier, and LoadMaster LTSF v7.2.54.17 and earlier.
What did CISA confirm about CVE-2026-8037?
CISA confirmed that CVE-2026-8037 was added to the Known Exploited Vulnerabilities catalog with confirmed exploitation, according to the record reflected by CISA and CIRCL. The entry lists Aug. 7, 2026 as the first observed date and identifies impact on Progress LoadMaster and Progress ECS Connections Manager.
The same CIRCL CVE database also shows that CVE-2026-63077 was added to KEV with confirmed exploitation and affects JetBrains TeamCity, while CVE-2026-20316 appears in the catalog with the same status for Cisco Secure Firewall Management Center. The three entries show CISA continuing to add flaws that have already been exploited in products widely used in enterprise environments.
What did Progress say about the vulnerability?
Progress said in security update AV26-552 that, in the case of CVE-2026-8037, the public report points to in-the-wild exploitation. In that same update, the company said CISA added the vulnerability to KEV on Aug. 7, 2026.
According to Progress’s published guidance, the flaw affects LoadMaster GA v7.2.63.1 and earlier, and LoadMaster LTSF v7.2.54.17 and earlier. The fixed versions released are GA v7.2.63.2 and LTSF v7.2.54.18.
AltonaSpain also reported that exploitation attempts have already been detected against this critical vulnerability in Progress Kemp LoadMaster, in line with Progress’s update and the CVE’s entry in the KEV catalog.
What does the KEV catalog context show?
CISA’s KEV catalog marks CVE-2026-8037 as confirmed, exploited, and first observed on Aug. 7, 2026, according to CIRCL. The entry covers Progress LoadMaster and Progress ECS Connections Manager, two infrastructure products that often become focal points when actively exploited flaws emerge.
The overlap between Progress’s advisory, the KEV listing, and the technical coverage published by AltonaSpain leaves CVE-2026-8037 as the latest case in the material reviewed to add confirmed exploitation in a security and load-balancing product that is widely deployed.
Sources
- Detectan intentos de explotación de una vulnerabilidad crítica en Progress Kemp LoadMasternews.altonaspain.es· AltonaSpain
- Progress security advisory (AV26-552) – Update 2csirts.com· CSIRTS.com
- Known Exploited Vulnerabilities Catalogcisa.gov· CISA
- CVE Brief - August 5, 2026cvebrief.com· CVE Brief
- Known Exploited Vulnerabilities Catalogcve.circl.lu· CVE Circl



