hacker-news · Crawled Aug 8, 2026
Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts
3 IoCs
Read original article ↗
AI Summary
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-8037, a critical command injection vulnerability in Progress Kemp LoadMaster, to its Known Exploited Vulnerabilities (KEV) catalog due to active exploitation. The flaw allows unauthenticated attackers to execute arbitrary commands on affected devices via unsanitized input in multiple command endpoints. A total of 792 exploitation attempts have been observed from 65 unique IP addresses across 18 countries, with recent activity detected as of August 4, 2026. Federal agencies are urged to patch by August 10, 2026, per BOD 26-04.
AI-extracted · verify before operational use