Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist

August 15, 2026

Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

August 15, 2026

Novel macOS Infostealer AmnesiaStealer Spread via ClickFix

August 14, 2026
Facebook X (Twitter) Instagram
Saturday, August 15
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts
News

Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

Team-CWDBy Team-CWDAugust 15, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild.

The vulnerability, tracked as CVE-2026-8037 (CVSS score: 9.6), is a command injection flaw that could be weaponized to achieve arbitrary code execution on susceptible devices.

“Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints,” CISA said.

In an analysis published in June 2026, watchTowr Labs described the issue as present in a function named “escape_quotes()” within the load balancer application and that it stemmed from improper handling of user-supplied input, ultimately enabling command injection.

Successful exploitation of the flaw can allow an unauthenticated attacker to run arbitrary commands on the affected appliance without having to possess valid credentials.

The addition comes a little over a month after eSentire said it’s seeing active exploitation efforts targeting the flaw, although it noted those efforts were largely unsuccessful.

The attacks originated from the following IP addresses, per the Canadian security vendor –

  • 192.42.116[.]58
  • 192.42.116[.]105
  • 146.70.139[.]154

According to telemetry data captured by KEVIntel, a total of 792 exploitation attempts have been observed over the last 41 days from 65 unique IP addresses from 18 countries, including Australia, China, Indonesia, Japan, Poland, and the U.S. The last activity was recorded on August 4, 2026, when five exploitation attempts were detected.

In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies are recommended to apply the necessary patches by August 10, 2026, to secure their networks in accordance with Binding Operational Directive (BOD) 26-04.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleNovel macOS Infostealer AmnesiaStealer Spread via ClickFix
Next Article N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
Team-CWD
  • Website

Related Posts

News

N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist

August 15, 2026
News

Novel macOS Infostealer AmnesiaStealer Spread via ClickFix

August 14, 2026
News

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

August 14, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA

July 11, 20268 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

What it is and how to protect yourself

January 8, 2026

What’s at stake if your employees post too much online

December 1, 2025

It’s all fun and games until someone gets hacked

September 26, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.