Search

Find merged stories by title or summary.

Vulnerabilities & Patches
Emerging1 src

ZDI-26-646: Progress Software Kemp LoadMaster escape_quotes Uninitialized Memory Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Progress Software Kemp LoadMaster. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7. 2. The following CVEs are assigned: CVE-2026-8037.

·Zero Day Initiative (Published)
Read →
Vulnerabilities & Patches
Emerging1 src

CISA Warns of Progress LoadMaster Command Injection Vulnerability Exploited in Attacks

CISA has added a critical Progress LoadMaster vulnerability to its Known Exploited Vulnerabilities catalog after attackers were observed targeting exposed devices. Tracked as CVE-2026-8037 , the flaw affects Progress LoadMaster and Progress ADC products. It is a command injection issue that could let an unauthenticated attacker run arbitrary commands on a vulnerable LoadMaster appliance. The vulnerability has a CVSS severity score of 9. 6, placing it in the critical category. LoadMaster is an application delivery controller and load balancer used by organizations to manage, distribute, and secure network traffic. Because these appliances often sit at critical network points, a successful compromise can provide attackers with a valuable path into an organization’s environment.

·Cyber Security News
Read →
Vulnerabilities & Patches
Emerging1 src

CISA warns Actively Exploited Progress Kemp LoadMaster RCE Flaw

The U. S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical command-injection vulnerability affecting Progress Kemp LoadMaster appliances to its Known Exploited Vulnerabilities (KEV) Catalog, warning that the flaw is being actively exploited in the wild. Tracked as CVE-2026-8037, the vulnerability allows an unauthenticated remote attacker to execute arbitrary operating system commands on affected LoadMaster appliances. Progress LoadMaster is an application delivery controller and load balancer commonly deployed at the network edge to distribute application traffic, provide SSL offloading, and manage availability.

·CyberPress
Read →
Vulnerabilities & Patches
Emerging1 src

U.S. CISA adds a Progress LoadMaster flaw to its Known Exploited Vulnerabilities catalog

U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Progress LoadMaster vulnerability to its Known Exploited Vulnerabilities catalog. The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added a Progress LoadMaster vulnerability, tracked as CVE-2026-8037 (CVSS score of 9. 6), to its Known Exploited Vulnerabilities (KEV) catalog . The vulnerability is an OS Command Injection Remote Code Execution issue that resides in API in Progress ADC Products. An unauthenticated attacker can trigger the flaw to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints In early July, cybersecurity firm eSentire observed exploitation attempts targeting CVE-2026-8037. Activity began June 29, 2026, but the attacks failed and no post-compromise activity was detected.

·Security Affairs
Read →
Vulnerabilities & Patches
Emerging1 src

Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

The U. S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. The vulnerability, tracked as CVE-2026-8037 (CVSS score: 9.6), is a command injection flaw that could be weaponized to achieve arbitrary

·The Hacker News
Read →
Vulnerabilities & Patches
Emerging1 src

CVE-2026-8037 - Progress LoadMaster Command Injection Vulnerability

Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.

·CISA KEV
Read →

You've reached the end of current stories for this search.