Search
Find merged stories by title or summary.
ZDI-26-646: Progress Software Kemp LoadMaster escape_quotes Uninitialized Memory Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Progress Software Kemp LoadMaster. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7. 2. The following CVEs are assigned: CVE-2026-8037.
CISA Warns of Progress LoadMaster Command Injection Vulnerability Exploited in Attacks
CISA has added a critical Progress LoadMaster vulnerability to its Known Exploited Vulnerabilities catalog after attackers were observed targeting exposed devices. Tracked as CVE-2026-8037 , the flaw affects Progress LoadMaster and Progress ADC products. It is a command injection issue that could let an unauthenticated attacker run arbitrary commands on a vulnerable LoadMaster appliance. The vulnerability has a CVSS severity score of 9. 6, placing it in the critical category. LoadMaster is an application delivery controller and load balancer used by organizations to manage, distribute, and secure network traffic. Because these appliances often sit at critical network points, a successful compromise can provide attackers with a valuable path into an organization’s environment.
CISA warns Actively Exploited Progress Kemp LoadMaster RCE Flaw
The U. S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical command-injection vulnerability affecting Progress Kemp LoadMaster appliances to its Known Exploited Vulnerabilities (KEV) Catalog, warning that the flaw is being actively exploited in the wild. Tracked as CVE-2026-8037, the vulnerability allows an unauthenticated remote attacker to execute arbitrary operating system commands on affected LoadMaster appliances. Progress LoadMaster is an application delivery controller and load balancer commonly deployed at the network edge to distribute application traffic, provide SSL offloading, and manage availability.
U.S. CISA adds a Progress LoadMaster flaw to its Known Exploited Vulnerabilities catalog
U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Progress LoadMaster vulnerability to its Known Exploited Vulnerabilities catalog. The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added a Progress LoadMaster vulnerability, tracked as CVE-2026-8037 (CVSS score of 9. 6), to its Known Exploited Vulnerabilities (KEV) catalog . The vulnerability is an OS Command Injection Remote Code Execution issue that resides in API in Progress ADC Products. An unauthenticated attacker can trigger the flaw to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints In early July, cybersecurity firm eSentire observed exploitation attempts targeting CVE-2026-8037. Activity began June 29, 2026, but the attacks failed and no post-compromise activity was detected.
Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts
The U. S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. The vulnerability, tracked as CVE-2026-8037 (CVSS score: 9.6), is a command injection flaw that could be weaponized to achieve arbitrary
CVE-2026-8037 - Progress LoadMaster Command Injection Vulnerability
Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.
You've reached the end of current stories for this search.
