cisaregulatorNewsThe Broadside2 min read

CISA adds Progress LoadMaster command injection to KEV catalog

BOD 26-04 makes the KEV catalog binding for federal agencies, not advisory, and the remediation clock starts now.


TL;DR

CISA added CVE-2026-8037, a command injection vulnerability in Progress LoadMaster, to its Known Exploited Vulnerabilities catalog on August 7. The vulnerability allows unauthenticated remote command execution on publicly exposed appliances. Federal civilian agencies now have a binding obligation under BOD 26-04 to prioritize patching it, the catalog has shifted from an advisory resource to a compliance framework with teeth. Contractors supporting federal networks should treat this as urgent: supply chain liability doesn't wait for a memo.

The addition of CVE-2026-8037 to the KEV catalog is routine, it's the 1,662nd entry. What changed is the machinery around it.

BOD 26-04, issued earlier this year, operationalizes the KEV catalog as a binding compliance requirement for Federal Civilian Executive Branch agencies. Before the directive, the catalog was a prioritization aid, useful, well-maintained, but ultimately a suggestion. Now every new KEV entry triggers a remediation clock. For this LoadMaster vulnerability, the due date CISA published is August 10, 2026. Three days. That timeline assumes the agency knows which of its assets are running LoadMaster and whether they're publicly exposed. For many, that's not a given.

The vulnerability itself is serious: unauthenticated command injection across multiple endpoints on the LoadMaster appliance. Progress has published mitigation guidance. CISA's action notice tells agencies to apply those mitigations, follow the forensics triage requirements in the BOD 26-04 implementation guidance, and discontinue use if mitigation isn't possible. The ransomware exploitation status is listed as "unknown," which means threat actors are actively using it but CISA hasn't yet tied it to a specific ransomware campaign.

What BOD 26-04 actually requires

The directive doesn't just say "patch faster." It imposes tiered obligations based on asset exposure and post-exploitation impact. Vulnerabilities on the KEV catalog affecting publicly exposed assets that grant total control after exploitation get top priority. Lower-risk vulnerabilities get deferred, explicitly. It's a risk-based triage framework codified as policy, and it comes with forensics requirements: agencies must check whether threat actors compromised the system before the patch was applied.

For contractors and C3PAOs supporting federal networks, BOD 26-04 doesn't apply directly, but the liability chain does. If a contractor runs LoadMaster on behalf of an FCEB agency and doesn't patch within the directive's timeline, the agency's noncompliance becomes the contractor's problem. The flow-down is implicit but real.

The open question

Whether BOD 26-04 applies retroactively to vulnerabilities already in the KEV catalog when the directive was issued, or only to new additions, remains unclear in the published text. The directive says agencies must prioritize CVEs "listed in CISA's KEV Catalog", present tense, which could cut either way. For now, the safe read is that every KEV entry, old or new, carries binding weight. Nobody wants to be the test case.


Published ·Deep Fathom