Skip to main content

Tag: cve 2026 8037

4 articles

Network operations center with integrated load balancer equipment.

Hackers Actively Exploit Critical LoadMaster Flaw in Global Attacks

Hackers are actively exploiting a critical flaw in LoadMaster, known as CVE-2026-8037, which allows them to run malicious commands on unpatched devices - putting your security at risk if you haven't updated yet. This vulnerability enables unauthenticated attackers to take control, making it crucial to patch Progress Kemp LoadMaster appliances ASAP.

Analyst 207
Network operations center equipment rack with loadmaster device and cabling.

CISA Warns of Active Progress Kemp LoadMaster Exploit Attempts

The US Cybersecurity and Infrastructure Security Agency (CISA) has sounded the alarm on a critical flaw in Progress Kemp LoadMaster, warning of a surge in exploitation attempts - 792 attempts in just 41 days - and adding the bug to its list of known exploited vulnerabilities. This highly severe vulnerability, with a CVSS score of 9.6, allows attackers to execute arbitrary commands on the LoadMaster appliance without authentication.

Analyst 207
Industrial control panel in foreground, with monitors and equipment in background.

Progress LoadMaster Flaw Sees Active Exploitation Attempts

A critical vulnerability in Progress Kemp LoadMaster, tracked as CVE-2026-8037, is under active exploitation attempts, with Canadian cybersecurity firm eSentire's Threat Response Unit detecting and thwarting attacks starting June 29, 2026. The attacks, though unsuccessful, raise concerns about potential future breaches given the vulnerability's high CVSS score of 9.6.

Analyst 207
Network operations room with load balancer appliance surrounded by standard networking equipment.

Progress LoadMaster Flaw Lets Attackers Run Root Commands Pre-Auth

A critical flaw in Progress Kemp LoadMaster, known as CVE-2026-8037, allows attackers to run root commands without authentication - but a patch is now available to fix this gaping security hole. This vulnerability, scoring a severe 9.8, can be exploited with a simple crafted API request.

Analyst 207