Progress Kemp LoadMaster management API unauthenticated command injection (CVSS 9.3) — BSI WID-SEC-2026-1812; no observed exploitation
cve · CVE-2026-8037
Coverage timeline
1
first 2026-06-09 → last 2026-06-09
Briefs
1
1 distinct
Sources cited
31
25 hosts
Sections touched
0
—
Co-occurring entities
0
no co-occurrence
Story timeline
- 2026-06-09CTI Daily Brief — 2026-06-09
Source distribution
- attack.mitre.org4 (13%)
- bleepingcomputer.com2 (6%)
- cert.ssi.gouv.fr2 (6%)
- nvd.nist.gov2 (6%)
- blog.talosintelligence.com1 (3%)
- cisa.gov1 (3%)
- dragos.com1 (3%)
- elastic.co1 (3%)
- other17 (55%)
External references
All cited sources (31)
- attack.mitre.orginlineSteal Application Access Tokenhttps://attack.mitre.org/techniques/T1528/
- attack.mitre.orginlineSteal Web Session Cookiehttps://attack.mitre.org/techniques/T1539/
- attack.mitre.orginlineWeb Session Cookiehttps://attack.mitre.org/techniques/T1550/004/
- attack.mitre.orginlineAdversary-in-the-Middlehttps://attack.mitre.org/techniques/T1557/
- bleepingcomputer.cominlineBleepingComputer 2026-05-05https://www.bleepingcomputer.com/news/security/new-stealthy-quasar-linux-malware-targets-software-developers/
- bleepingcomputer.cominlineBleepingComputer, 2026-05-15https://www.bleepingcomputer.com/news/security/pwn2own-day-two-hackers-demo-microsoft-exchange-windows-11-red-had-enterprise-linux-zero-days/
- blog.talosintelligence.cominlineCisco Talos 2026-05-05https://blog.talosintelligence.com/uat-8302/
- cert.ssi.gouv.frinlineCERT-FR, 2026-05-05https://www.cert.ssi.gouv.fr/
- cert.ssi.gouv.frinlineCERT-FR CERTFR-2026-AVI-0542https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0542/
- cisa.govinlineCISA KEV (added 2026-05-15)https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- dragos.cominlineDragos, 2026-05-06https://www.dragos.com/blog/ai-assisted-ics-attack-water-utility/
- elastic.coinlineElastic Security Labs 2026-05-07https://www.elastic.co/security-labs/tclbanker-brazilian-banking-trojan
- enisa.europa.euinlineENISA NIS360 2026https://www.enisa.europa.eu/enisa-nis360-2026
- helpnetsecurity.cominlineHelp Net Securityhttps://www.helpnetsecurity.com/2026/05/04/critical-moveit-automation-auth-bypass-vulnerability-fixed-cve-2026-4670/
- huntress.cominlineHuntresshttps://www.huntress.com/blog/malspam-to-deskcvb-rat-delivery-chain-analysis
- industrialcyber.coinlineIndustrial Cyber, 2026-06-05https://industrialcyber.co/regulation-standards-and-compliance/eu-council-to-examine-cybersecurity-package-focused-on-enisa-nis2-simplification-and-supply-chain-security/
- kodemsecurity.cominlineKodem Security frames the AI-agent escalation pathhttps://www.kodemsecurity.com/resources/vm2-sandbox-escape-vulnerabilities-the-2026-cve-wave-turning-ai-agents-into-host-rce-vectors
- mi5.gov.ukinlineMI5https://www.mi5.gov.uk/five-eyes-joint-bulletin-safeguarding-our-secrets
- microsoft.cominlineMicrosoft Security Blog 2026-05-04https://www.microsoft.com/en-us/security/blog/2026/05/04/breaking-the-code-multi-stage-code-of-conduct-phishing-campaign-leads-to-aitm-token-compromise/
- msrc.microsoft.cominlineMSRC CVE-2026-42897https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-42897
- nvd.nist.govinlineNVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-5174
- nvd.nist.govinlineNVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-6023
- oasis.securityinlineOasis Security 2026-05-07https://www.oasis.security/blog/cline-kanban-websocket-hijack
- securityaffairs.cominlineSecurity Affairs — NIS360https://securityaffairs.com/193002/reports/enisa-nis360-2026-progress-across-the-board-but-the-sectors-that-matter-most-are-still-falling-short.html
- securitylabs.datadoghq.cominlineDatadog Security Labshttps://securitylabs.datadoghq.com/articles/shai-hulud-open-source-framework-static-analysis/
- thehackernews.cominlineThe Hacker News 2026-05-04https://thehackernews.com/2026/05/progress-patches-critical-moveit.html
- therecord.mediainlineThe Record, 2026-06-03https://therecord.media/five-eyes-warns-chinese-spies-are-using-job-sites-to-recruit-insiders
- upguard.cominlineUpGuardhttps://www.upguard.com/news/world-food-programme-data-breach-2026-06-02
- wid.cert-bund.deinlineBSI WID-SEC-2026-1583https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1583
- wiz.ioinlineWiz Researchhttps://www.wiz.io/blog/dirty-frag-linux-kernel-local-privilege-escalation-via-esp-and-rxrpc
- zerodayinitiative.cominlineZero Day Initiative, 2026-05-15https://www.zerodayinitiative.com/blog/2026/5/15/pwn2own-berlin-2026-day-two-results
Items in briefs about Progress Kemp LoadMaster management API unauthenticated command injection (CVSS 9.3) — BSI WID-SEC-2026-1812; no observed exploitation
No parsed item heading or body matches this entity yet. Items match by exact CVE id (for CVE entities), by lead-segment substring of the title in the item heading or body, or by a distinctive anchor token from the title appearing in the item heading. Coverage that lives inside a broader section (no per-item heading) is captured by the Story timeline above.