Security News

Cybersecurity news aggregator

CRITICAL Vulnerabilities SC Media

Progress Kemp LoadMaster vulnerability actively exploited

The critical vulnerability CVE-2026-8037 (CVSS 9.6) in Progress Kemp LoadMaster is an OS command injection flaw in the `/accessv2` endpoint, allowing unauthenticated attackers to execute arbitrary commands via unsanitized input. Affected versions are LoadMaster 7.2.48.1 through 7.2.48.9, 7.2.54.0 through 7.2.54.7, and 7.2.55.0 through 7.2.59.1. The flaw is fixed in versions 7.2.48.10, 7.2.54.8, and 7.2.59.2.
Read Full Article →

Vulnerability Management Progress Kemp LoadMaster vulnerability actively exploited July 1, 2026 Share By SC Staff According to The Hacker News, eSentire reports that a critical security flaw affecting Progress Kemp LoadMaster devices is currently being targeted by exploitation attempts. The vulnerability, identified as CVE-2026-8037, allows for arbitrary code execution on affected appliances. The operating system command injection flaw, with a CVSS score of 9.6, enables unauthenticated attackers to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input. Progress detailed the vulnerability, noting it stems from improper handling of user-supplied input within a function named "escape_quotes()", which fails to properly null-terminate sanitized strings. This can lead to an out-of-bounds read into adjacent heap memory, allowing attackers to issue specially crafted requests to the "/accessv2" endpoint to achieve command injection. While initial exploitation attempts observed by eSentire's Threat Response Unit ended in failure, the availability of a proof-of-concept exploit is expected to increase malicious activity. This marks the second critical Progress Kemp LoadMaster vulnerability to see active exploitation this year, following CVE-2024-1212. Source: The Hacker News SC Staff Related Vulnerability Management Critical Oracle E-Business Suite bug actively exploited Steve Zurier June 30, 2026 Critical Oracle EBS flaw now exploited, prompting urgent patching guidance. Vulnerability Management Anonymous researcher dumps zero-day exploits for multiple software products SC Staff June 30, 2026 The disclosed exploits include a critical pre-authentication remote code execution vulnerability in libssh2 (CVE-2026-55200) and an authentication bypass vulnerability in self-hosted Gitea Docker deployments (CVE-2026-20896), which allows attackers to impersonate users and take over Git servers. Patch/Configuration Management Microsoft extends Windows Server 2022 hotpatching to 2027 SC Staff June 29, 2026 Microsoft will continue to offer hotpatching for Windows Server 2022 Datacenter: Azure Edition until 2027, a move that extends support beyond the mainstream end date of October 13, 2026. Related Events Cybercast Why Mythos is the cybersecurity crisis we need Wed Jul 22 Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Bug Buffer Overflow Disassembly You can skip this ad in 5 seconds

Share this article