AI Stories on SHORT INFO are generated & curated with AI
unverified 11 Aug, 07:10

Progress Kemp LoadMaster zero-day CVE-2026-8037 hits CISA KEV list after 792 exploitation attempts

Every internet-exposed Progress Kemp LoadMaster $PRGS load balancer left unpatched is a live target. CISA added CVE-2026-8037 (CVSS 9.6) to its Known Exploited Vulnerabilities catalog on August 7. KEVIntel logged 792 exploit attempts from 65 IPs in 41 days, per The Hacker News.

A critical vulnerability in Progress Kemp LoadMaster, a widely deployed network load balancer, is now under active exploitation and has landed on the U.S. Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalog. CVE-2026-8037 carries a CVSS score of 9.6. The flaw is a command injection vulnerability rooted in the appliance's escape_quotes() function, which fails to properly handle user-supplied input, according to an analysis published by watchTowr Labs in June. Exploiting it lets an unauthenticated attacker run arbitrary commands on the device without needing valid credentials. CISA added the vulnerability to its KEV catalog on August 7, following reports of active exploitation. Telemetry from KEVIntel, cited by The Hacker News, recorded 792 exploitation attempts from 65 unique IP addresses spread across 18 countries, including Australia, China, Indonesia, Japan, Poland, and the United States, over a 41-day period. The most recent activity was logged on August 4. Federal civilian executive branch agencies were required to apply patches by August 10 under Binding Operational Directive 26-04, a deadline that has now passed. Progress Software $PRGS issued fixed versions in June: LoadMaster GA 7.2.63.2 and LTSF 7.2.54.18. Any organization still running LoadMaster as an internet-facing load balancer without that update remains exposed, regardless of whether it falls under the federal patching mandate.

Published on
RedditBlueskyThreadsXFacebook