CISA Adds One Known Exploited ... Note

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added a new vulnerability, CVE-2026-8037, concerning Progress LoadMaster Command Injection, to its Known Exploited Vulnerabilities catalog. This vulnerability is actively being exploited by malicious actors and poses a significant risk. Binding Operational Directive 26-04 mandates that Federal Civilian Executive Branch agencies prioritize fixing vulnerabilities listed in the KEV catalog. This directive emphasizes rapid remediation of high-risk vulnerabilities on publicly exposed assets that lead to full control after exploitation. Agencies are also required to check for compromises before applying patches. While BOD 26-04 specifically targets FCEB agencies, CISA urges all organizations to adopt a risk-based approach to vulnerability management. They encourage prioritizing the remediation of KEV cataloged vulnerabilities. CISA will continue to add vulnerabilities that meet the criteria for active exploitation. Organizations aware of exploited vulnerabilities not yet in the catalog can submit them for consideration. These nominations require a CVE ID, proof of exploitation, and clear mitigation steps.