CVE-2026-8037 in Progress Kemp LoadMaster allows pre-auth root command execution via API; patches are available and a public PoC is out.

CVE-2026-8037 in Progress Kemp LoadMaster allows pre-auth root command execution via API; patches are available and a public PoC is out.

eSentire says attacks began June 29 against a CVSS 9.6 OS command injection flaw that enables unauthenticated code execution.

Introduction: Unveiling the Critical Vulnerability The recently identified CVE-2026-8037...