TRENDING
Rows of identical brass-colored apartment mailboxes with small locks and name labels along an orange corridor wall
October 9, 2026
How to Prevent Broken Object Level Authorization (IDOR) in a FastAPI App
Street-level upward view of the Monetary Authority of Singapore building and neighbouring office towers under a pale sky
October 9, 2026
Singapore’s AI Guidelines Turn Independent Review Into a Question of Who Sets the Risk Rating
Cast-iron late Qing dynasty coin minting press with a large flywheel, displayed in a museum case
October 9, 2026
Attackers Hijacked the .gh, .sl and .as Country Domains and Minted HTTPS Certificates for Google
Rows of closed oak library card catalog drawers, each with a brass pull and a blank label holder
October 9, 2026
How to Encrypt PII in Python and Keep It Searchable With Blind Indexes
Close-up of a vintage Western Electric manual telephone switchboard with orange lamps, red patch cords plugged into jacks, a rotary dial and a black handset
October 9, 2026
Microsoft’s Agent Lightning v1.0 Turns Agent Training Into a Sample-Accounting Problem
09 Oct 2026
SXZ.io SXZ.io
  • Home
Search the Site
Popular Searches:
Technology Amazon AI
Recent Posts
Two orange safety relief valves on grey pressure vessels in an industrial plant
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
October 8, 2026
Yellow diamond-shaped merging traffic warning sign showing a side road joining a main road
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
October 8, 2026
A lugworm lying on wet sand and mud at low tide
A Compromised Admin Account Put the Shai-Hulud Worm Into AI Sandbox Maker Tensorlake’s npm SDK
October 8, 2026
SXZ.io SXZ.io
  • Home

Categories

Articles 232 Posts
News 234 Posts
Learning Hub 204 Posts
Home/News/CISA Orders Federal Agencies to Patch a Critical Kemp LoadMaster Flaw Under Active Attack
News

CISA Orders Federal Agencies to Patch a Critical Kemp LoadMaster Flaw Under Active Attack

CISA added a critical, actively exploited Kemp LoadMaster command injection flaw to its must-patch catalog, giving federal agencies a same-day deadline while independent telemetry shows six weeks of...

August 10, 2026 3 Min Read
39

The U.S. Cybersecurity and Infrastructure Security Agency added a critical Progress Kemp LoadMaster vulnerability to its Known Exploited Vulnerabilities catalog on August 7, giving federal civilian agencies until today, August 10, to patch it under Binding Operational Directive 26-04. The deadline, first detailed by BleepingComputer, arrives as independent telemetry shows attackers have been probing the flaw for six weeks.

Table Of Content

  • An Uninitialized Buffer Turns Into Pre-Auth RCE
  • Exploitation Has Been Running for Weeks
  • A Federal Deadline, and a Warning for Everyone Else

An Uninitialized Buffer Turns Into Pre-Auth RCE

Tracked as CVE-2026-8037 and rated 9.6 out of 10 on the CVSS scale, the flaw lets an unauthenticated attacker execute arbitrary commands on a Kemp LoadMaster appliance by exploiting unsanitized input across multiple API command endpoints, including the appliance’s /accessv2 endpoint, according to watchTowr Labs’ research. Kemp LoadMaster is a widely deployed application delivery controller and load balancer: Progress Software says 80 percent of Fortune 500 companies use its products and services, and the LoadMaster line alone has more than 100,000 deployments worldwide, including at Amazon and the U.S. Air Force, according to BleepingComputer.

A technical analysis from watchTowr Labs, published in June, traces the root cause to escape_quotes(), a function meant to sanitize input before it reaches a shell command. The function allocated its output buffer with malloc() rather than a zeroing allocator and never null-terminated the escaped string it produced. watchTowr’s researchers found that sending four single quotes as the API’s apiuser value expanded into 16 unterminated bytes that could overwrite the metadata of an adjacent freed memory chunk. By simultaneously spraying command-injection payloads across other API parameters, an attacker could get one payload to land next to that corrupted buffer, so the unterminated string read continued straight into it and executed the payload through a system() call. Progress fixed the bug in LoadMaster GA v7.2.63.2 and LTSF v7.2.54.18 by switching to a zeroing allocator and adding the missing null terminator. Versions GA v7.2.63.1 and LTSF v7.2.54.17 and earlier remain vulnerable, as does every version of Progress’s MOVEit WAF before GA v7.2.63.2.

Exploitation Has Been Running for Weeks

Progress disclosed the vulnerability and shipped a patch for it on June 4. That changed on June 29, when a functional proof-of-concept exploit went public. eSentire’s Threat Response Unit says it began detecting exploitation attempts that same day, tracing early activity to three IP addresses; in the intrusions it observed, “exploitation was not successful, and as such, no post-compromise activity was observed.”

The activity has not let up since. Threat-intelligence platform KEVIntel has logged 792 exploitation attempts over 41 days from 65 unique IP addresses in 18 countries, including Australia, China, Indonesia, Japan, Poland, and the United States, with the most recent burst of five attempts recorded on August 4, according to The Hacker News. Internet-scanning service Shadowserver counted nearly 300 Kemp LoadMaster instances still exposed online as of BleepingComputer’s report, though it could not say how many were honeypots or had already been patched.

A Federal Deadline, and a Warning for Everyone Else

BOD 26-04 formally binds only Federal Civilian Executive Branch agencies, which CISA is requiring to secure any LoadMaster or MOVEit WAF deployment by the end of today. “This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise,” CISA said in the alert accompanying the catalog addition. The directive does not bind anyone outside government, but CISA urged all defenders running an unpatched, internet-facing appliance to prioritize patching CVE-2026-8037 regardless, a call made more urgent by how many instances are still sitting exposed six weeks after working exploit code became public.

Tags:

CISACommand Injectionkemp-loadmasterprogress-softwareVulnerability Management

Share

Close-up photo of a Raspberry Pi single-board computer, representing the kind of small edge hardware that compact AI models like LFM2.5-2.6B are designed to run on
Previous Post

How to Build a Local Tool-Calling AI Agent With LFM2.5-2.6B and Hugging Face Transformers

MIT's Stata Center, home to CSAIL, the computer science and AI lab where Liquid AI cofounder Ramin Hasani conducts research
Next Post

Five Startups Turn Transformer Compute Costs Into an Architecture Race

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest
08 Oct
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
08 Oct
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
Trending
October 8, 2026
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
October 8, 2026
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
October 8, 2026
A Compromised Admin Account Put the Shai-Hulud Worm Into AI Sandbox Maker Tensorlake’s npm SDK
October 8, 2026
How to Prevent Broken Object Level Authorization (IDOR) in a FastAPI App
October 8, 2026
Singapore’s AI Guidelines Turn Independent Review Into a Question of Who Sets the Risk Rating
October 8, 2026
Attackers Hijacked the .gh, .sl and .as Country Domains and Minted HTTPS Certificates for Google

Related Posts

Rows of server racks in a data center representing network infrastructure targeted by botnets
News

C0XMO Botnet Shows Why Old Router Firmware Still Matters

June 7, 2026
Close-up of a USB flash drive, representing physical data-theft risk in office security incidents
News

Fake IT Support Is Now Walking Through the Front Door

June 7, 2026
A phone security app on a smartphone resting on a laptop keyboard.
News

Everest Forms Pro Flaw Is Being Exploited to Create Rogue WordPress Admins

June 7, 2026
A phone secured by a padlock, illustrating AI data-leak containment and security controls.
News

OpenAI’s Lockdown Mode Is a Data-Leak Brake, Not a Prompt-Injection Cure

June 8, 2026
SXZ.io SXZ.io
  • [email protected]

Categories

Articles
Learning Hub
News

All Rights Reserved by SXZ.io ©2026