← All posts

The 25-Day Window Your Board Doesn't Know About

On June 4, Progress Software published a security advisory for a critical vulnerability in its Kemp LoadMaster product — a load balancer deployed in over 100,000 environments worldwide. The flaw, CVE-2026-8037, scored a 9.8 out of 10 on the severity scale. No credentials required. Fully remote. Root-level access to the appliance.

A patch was available the same day.

Twenty-five days later, on June 29, attackers began exploiting it in the wild.

That 25-day gap is the story. Not the vulnerability itself — those come and go. The question for every executive reading this is straightforward: Would your organization have patched in time?

The Infrastructure You Forgot About

Most boards have gotten comfortable asking about endpoint protection, cloud security, even AI governance. That's progress. But load balancers? Application delivery controllers? These sit in the plumbing of your network, routing traffic between users and the applications they depend on. They're invisible until they break — or until someone takes them over.

Kemp LoadMaster is widely deployed across mid-market and enterprise environments. It handles SSL offloading, traffic distribution, and web application firewall duties. When an attacker owns this device, they don't just see traffic. They control it. They can intercept data, redirect users, pivot deeper into your network — all without triggering the alerts your security team is watching.

In my experience, these infrastructure appliances are the ones that fall through the cracks. They get deployed, they work, and nobody touches them for years. Patching a load balancer means a maintenance window, potential downtime, change management paperwork. So the patch sits in a queue while the team handles the "urgent" stuff.

Twenty-five days is a long time when the front door is unlocked.

What the Three Questions Framework Tells Us

In Cyber Risk Is Business Risk, I introduce a simple framework any executive can use to cut through the noise: What do we have? How are we protecting it? What happens when something goes wrong?

Applied to this situation:

What do we have? If your CISO can't tell you within 24 hours whether your organization runs Kemp LoadMaster — and which version — that's an asset management problem masquerading as a security problem. You can't patch what you don't know you own.

How are we protecting it? The vulnerability sits in an API endpoint. Is that endpoint exposed to the internet? Does your team have a defined SLA for patching critical infrastructure? Is there a difference between how quickly you patch a laptop and how quickly you patch a network appliance? There shouldn't be — but in most organizations, there is.

What happens when something goes wrong? If an attacker compromised your load balancer tomorrow, would your detection tools even notice? Most endpoint detection and response platforms don't monitor network appliances. Your SOC might be watching the wrong screens entirely.

The Board Conversation That Needs to Happen

Here's what concerns me about stories like this: they don't make the board deck. A critical vulnerability in a load balancer doesn't sound like a business risk. It sounds like an IT issue — something the infrastructure team handles.

But the SEC doesn't see it that way. Under the current disclosure rules, a breach that starts with an unpatched appliance is a material event. And if your board was never told that critical patches were sitting undeployed for weeks, the oversight question gets uncomfortable fast.

Shareholder derivative suits increasingly target exactly this pattern: a known vulnerability, an available patch, a delay in deployment, and a breach that follows. The argument writes itself — the fix existed, the risk was documented, and nobody escalated it.

This isn't hypothetical. We've watched this playbook unfold with Fortinet, with Oracle, with JetBrains. The vendor publishes the advisory, the clock starts ticking, and the organizations that treat patching as a priority survive. The ones that treat it as a chore end up in the headlines.

What to Ask Your CISO This Week

If you're an executive or board member, here are three questions worth raising at your next meeting:

"Do we have a complete inventory of network appliances — load balancers, firewalls, VPN concentrators — and are they included in our patch management program?" If the answer is anything other than yes, you have a blind spot.

"What's our SLA for deploying critical patches to infrastructure devices, and how does it compare to our SLA for endpoints and servers?" In many organizations, laptops get patched in days. Network appliances get patched in quarters. That gap is where breaches happen.

"Are we monitoring network appliances for indicators of compromise, or are they outside the scope of our detection tools?" A compromised load balancer is invisible to most security monitoring. If your team isn't specifically looking, they won't find it.

The Bigger Picture

CVE-2026-8037 will be forgotten in a month. Another critical vulnerability will take its place. That's the cycle.

The executive question isn't about any single CVE. It's about whether your organization has the discipline to close a 25-day window before an attacker walks through it. That's a process question, a resource question, and — increasingly — a fiduciary question.

The patch was available on day one. The only variable was whether someone deployed it.