Security Affairs
Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data|U.S. CISA adds a Progress LoadMaster flaw to its Known Exploited Vulnerabilities catalog|Unlimited Technology Systems Data Breach Exposes Data of 3.8 Million Healthcare Patients|WordPress XSS2Shell Flaw Turns Simple Login Bug Into Full Server Takeover|Hackers Impersonate IT Support to Breach Leading Financial Companies|Meta Ordered to Pay $567 Million Over Child Safety Failures in New Mexico Case|Researchers Discover Hidden Backdoor in 20 Router Models Allowing Remote Root Access|AI Deepfakes Used to Impersonate OnlyFans Creators in New Scam|Exposed SISVISA Database Leaks 102,000 Brazilian Health Surveillance Records|Ransom Cartel Leader Sentenced to 16 Years in U.S.|Meta AI Model Hacked a Company During Testing, Marking Third AI Lab Incident|U.S. CISA adds a JetBrains TeamCity flaw to its Known Exploited Vulnerabilities catalog|Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data|U.S. CISA adds a Progress LoadMaster flaw to its Known Exploited Vulnerabilities catalog|Unlimited Technology Systems Data Breach Exposes Data of 3.8 Million Healthcare Patients|WordPress XSS2Shell Flaw Turns Simple Login Bug Into Full Server Takeover|Hackers Impersonate IT Support to Breach Leading Financial Companies|Meta Ordered to Pay $567 Million Over Child Safety Failures in New Mexico Case|Researchers Discover Hidden Backdoor in 20 Router Models Allowing Remote Root Access|AI Deepfakes Used to Impersonate OnlyFans Creators in New Scam|Exposed SISVISA Database Leaks 102,000 Brazilian Health Surveillance Records|Ransom Cartel Leader Sentenced to 16 Years in U.S.|Meta AI Model Hacked a Company During Testing, Marking Third AI Lab Incident|U.S. CISA adds a JetBrains TeamCity flaw to its Known Exploited Vulnerabilities catalog|
Advertisement

Ad Placeholder

Full Width × 90

Breaking News

U.S. CISA adds a Progress LoadMaster flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Progress LoadMaster vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Progress LoadMaster vulnerability, tracked as CVE-2026-8037 (CVSS score of 9.6), to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerability is an OS Command Injection Remote Code Execution issue […]

CISA Minnesota Attacks

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Progress LoadMaster vulnerability to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Progress LoadMaster vulnerability, tracked as CVE-2026-8037 (CVSS score of 9.6), to its Known Exploited Vulnerabilities (KEV) catalog.

The vulnerability is an OS Command Injection Remote Code Execution issue that resides in API in Progress ADC Products. An unauthenticated attacker can trigger the flaw to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints

In early July, cybersecurity firm eSentire observed exploitation attempts targeting CVE-2026-8037. Activity began June 29, 2026, but the attacks failed and no post-compromise activity was detected. Researchers warned that the public PoC and technical details could lead to increased exploitation.

“Beginning on June 29th, 2026, eSentire’s Threat Response Unit (TRU) identified exploitation attempts targeting the critical Progress Kemp LoadMaster vulnerability CVE-2026-8037. The vulnerability was initially disclosed on June 4th and functional Proof-of-Concept (PoC) exploit code was released on June 29th. CVE-2026-8037 (CVSS: 9.6), is an OS Command Injection Remote Code Execution (RCE) vulnerability which allows an unauthenticated attacker to execute arbitrary commands on the LoadMaster appliance.” eSentire reports.

“As active exploitation attempts have been identified, it is critical that organizations apply the relevant security patches immediately.”

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the vulnerability by the end of this week, on August 10, 2026.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)