Progress security advisory (AV26-552) – Update 2

Serial number: AV26-552
Date: June 5, 2026
Updated: Auguest 7, 2026

Between June 2 and 4, 2026, Progress published security advisories to address vulnerabilities in the following products. Included was a critical update for the following:

  • Sitefinity CMS and Sitefinity Insight – multiple versions
  • Progress Kemp LoadMaster – version GA v7.2.63.1 and prior
  • Progress Kemp LoadMaster - version LTSF v7.2.54.17 and prior

Update 1

Open-source reporting indicates that CVE-2026-8037 is being exploited in the wild.

Update 2

On August 7, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-8037 to their Known Exploited Vulnerabilities (KEV) Database.

The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.

Date modified: