Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth

A critical vulnerability in Progress Kemp LoadMaster can let an unauthenticated attacker execute arbitrary commands as root on the appliance by sending a crafted request to its API.

The flaw, tracked as CVE-2026-8037, carries a CVSS score of 9.8 according to ZDI. A patch is available. If you run LoadMaster with the API enabled, update now.

Progress published its advisory on June

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Cyberdecks, going analog, and convivial technology

Cyberdecks, going analog, and convivial technology Source: Hacker News

Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents

Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents A flaw in four widely used AI coding agents lets someone who controls a plugin’s code repository

Muse, the band, lost its social media handles to Muse, Meta’s new AI agent

Muse, the band, lost its social media handles to Muse, Meta’s new AI agent Source: Hacker News