{"id":2294,"date":"2026-08-08T12:40:11","date_gmt":"2026-08-08T12:40:11","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2294"},"modified":"2026-08-08T12:40:11","modified_gmt":"2026-08-08T12:40:11","slug":"progress-kemp-loadmaster-flaw-hits-cisa-kev-after-792-reported-exploit-attempts","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2294","title":{"rendered":"Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Aug 08, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Network Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg_DF22WirQj4KZe5A4NxYmG3UhC2o4BRQ4AybyFlmr80n5Wkf15sbtMn11P0msoMyAe65WBqMpL2XBsqTiHdDNNH1i6qz11ydD9X4AIOoiaSfCYb1MCe7dfJD0n4TEIc5_83tsMq5zJ5zVpGbpCq7b8rACen1oMvW8XGBbz3T4hy_9J6igpOk0oCDp6vkA\/s1700-e365\/progress.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday <a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2026\/08\/07\/cisa-adds-one-known-exploited-vulnerability-catalog\" target=\"_blank\">added<\/a> a critical-severity security flaw impacting Progress\u202fKemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild.<\/p>\n<p>The vulnerability, tracked as <strong>CVE-2026-8037<\/strong> (CVSS score: 9.6), is a command injection flaw that could be weaponized to achieve arbitrary code execution on susceptible devices.<\/p>\n<p>\u00abProgress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints,\u00bb CISA <a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" target=\"_blank\">said<\/a>.<\/p>\n<p>In an analysis published in June 2026, watchTowr Labs described the issue as present in a function named \u00abescape_quotes()\u00bb within the load balancer application and that it stemmed from improper handling of user-supplied input, ultimately enabling command injection.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/threatlocker-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh5OTk93vfDmhLLtqoMsx4w59kseqsUysQ92SKB-S2vDoKsMmMfCCkx8AbG5MFzFvZ7rkzKd5LtgOCxlRF2FJ-0FArsVhpOnTMX31VBi9TX-z1Pgv9oSvXiT23KyDlxtVqI0dPRdMIuWc9fbNWgQF8CisKtMme0LpNr79b4wRaeDRxCjfGB8GsxfXa8Ltro\/s728-e100\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Successful exploitation of the flaw can allow an unauthenticated attacker to run arbitrary commands on the affected appliance without having to possess valid credentials.<\/p>\n<p>The addition comes a little over a month after eSentire said it&#8217;s seeing active exploitation efforts targeting the flaw, although it noted those efforts were largely unsuccessful.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj9kznm070QWLImYugPLRf-xFW3piianeH7cbVxaKFy9wU_eVapbC05TSNlMlbO0qReI-ouPlGVhpKJRe4jBjf2hrCJ_lfzMikotJi5TqEweQFCBm9yKJKbgMyJSUU-MqzT2Z2yA4fHmzflHiwArfFPhzyRAXmhDeryyqNzEEZjfGgUPzG62psne_E9AtuG\/s1700-e365\/cisa-attacks.jpg\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj9kznm070QWLImYugPLRf-xFW3piianeH7cbVxaKFy9wU_eVapbC05TSNlMlbO0qReI-ouPlGVhpKJRe4jBjf2hrCJ_lfzMikotJi5TqEweQFCBm9yKJKbgMyJSUU-MqzT2Z2yA4fHmzflHiwArfFPhzyRAXmhDeryyqNzEEZjfGgUPzG62psne_E9AtuG\/s1700-e365\/cisa-attacks.jpg\" alt=\"\" border=\"0\" data-original-height=\"746\" data-original-width=\"1944\"\/><\/a><\/div>\n<p>The attacks originated from the following IP addresses, per the Canadian security vendor &#8211;<\/p>\n<ul>\n<li>192.42.116[.]58<\/li>\n<li>192.42.116[.]105<\/li>\n<li>146.70.139[.]154<\/li>\n<\/ul>\n<p>According to <a href=\"https:\/\/kevintel.com\/CVE-2026-8037\" target=\"_blank\">telemetry data<\/a> captured by KEVIntel, a total of 792 exploitation attempts have been observed over the last 41 days from 65 unique IP addresses from 18 countries, including Australia, China, Indonesia, Japan, Poland, and the U.S. The last activity was recorded on August 4, 2026, when five exploitation attempts were detected.<\/p>\n<p>In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies are recommended to apply the necessary patches by August 10, 2026, to secure their networks in accordance with Binding Operational Directive (BOD) 26-04.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Aug 08, 2026Vulnerability \/ Network Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress\u202fKemp LoadMaster to its Known Exploited Vulnerabilities&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2295,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[1202,62,120,70,825,2250,203,2251,1513,2966],"class_list":["post-2294","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-attempts","tag-cisa","tag-exploit","tag-flaw","tag-hits","tag-kemp","tag-kev","tag-loadmaster","tag-progress","tag-reported"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2294","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2294"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2294\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2295"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2294"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2294"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2294"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}