Analyst Guidance
CVE-2026-8037 in Progress Kemp LoadMaster represents a critical command injection flaw with 792+ reported exploit attempts. Organizations should prioritize patching known exploited vulnerabilities and monitor for evidence of compromise on exposed systems.
CVE Details & Remediation
How to read this report
🛡️Verified facts — NVD & CISA KEV
⏳Partially verified — awaiting NVD enrichment
🧠AI analysis — synthesis, verify before acting
🛡️Actionable · Verified facts
NVD-published · CISA KEV cross-checked🛡️CVE-2026-16812 – Arista VeloCloud Orchestrator ✓ NVD
CVSS10 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS1% · P56
ActionPatch immediately
AffectedTechnology
Remediation Steps
- Apply the vendor security update for Arista VeloCloud Orchestrator On-Prem as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-15409 – SonicWall SMA1000 Appliances ✓ NVD
CVSS10 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS78% · P100
ActionPatch immediately
AffectedTechnology Finance
Remediation Steps
- Apply the vendor security update for SonicWall SMA1000 Appliances as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-48282 – Adobe ColdFusion ✓ NVD
CVSS10 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS99% · P100
ActionPatch immediately
Remediation Steps
- Apply the latest security patch from Adobe for ColdFusion path traversal vulnerability
- Implement input validation and sanitization on all file path parameters
- Restrict directory access permissions to the minimum required
- Review recent application logs for path traversal exploitation attempts
References:
🛡️CVE-2026-8037 – Progress LoadMaster ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ● New this week ★ Added to KEV this week
EPSS99% · P100
ActionPatch immediately
Remediation Steps
- Apply the latest security patch from Progress Software immediately
- Restrict network access to Kemp LoadMaster administration and API endpoints to trusted networks only
- Monitor systems for evidence of command injection exploitation (suspicious process execution, unexpected system changes)
- Review access logs and alert on failed and successful authentication attempts
- Perform forensic analysis on potentially compromised systems for persistence mechanisms
References:
- https://www.esentire.com/security-advisories/progress-kemp-loadmaster-vulnerability-targeted-cve-2026-8037
- https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691
- https://labs.watchtowr.com/enterprise-tech-in-shell-out-progress-kemp-loadmaster-uninitialized-heap-to-pre-auth-rce-cve-2026-8037/
🛡️CVE-2026-63077 – JetBrains TeamCity ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ● New this week ★ Added to KEV this week
EPSS1% · P60
ActionPatch immediately
Remediation Steps
- Review the CISA Known Exploited Vulnerabilities catalog entry for detailed product and version information
- Contact affected vendor for patch guidance and timeline
- Apply vendor patch upon availability
- Monitor systems for exploitation attempts
References:
🛡️CVE-2026-34486 – Apache Tomcat ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ● New this week ★ Added to KEV this week
EPSS81% · P100
ActionPatch immediately
AffectedTechnology Government
Remediation Steps
- Apply the vendor security update for Apache Tomcat as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-9198 – IBM Langflow ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ● New this week ★ Added to KEV this week
EPSS17% · P97
ActionPatch immediately
AffectedTechnology Government
Remediation Steps
- Apply the vendor security update for Langflow as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-50522 – Microsoft SharePoint ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS77% · P100
ActionPatch immediately
AffectedTechnology Finance
Remediation Steps
- Apply the vendor security update for Microsoft Sharepoint Server as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-0770 – Langflow ✓ NVD
CVSS9.8 NVD 3.0
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS56% · P99
ActionPatch immediately
AffectedGovernment Technology
Remediation Steps
- Apply the vendor security update for Langflow as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-63030 – WordPress Core ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS96% · P100
ActionPatch immediately
AffectedTechnology Government
Remediation Steps
- Apply the vendor security update for WordPress Core as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-25089 – Fortinet FortiSandbox ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS74% · P99
ActionPatch immediately
Remediation Steps
- Apply the vendor patch immediately per Fortinet's security advisory
References:
🛡️CVE-2026-39808 – Fortinet FortiSandbox ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS91% · P100
ActionPatch immediately
AffectedTechnology
Remediation Steps
- Apply the vendor security update for Fortinet Fortisandbox as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-46817 – Oracle E-Business Suite ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS13% · P96
ActionPatch immediately
AffectedGovernment Transportation
Remediation Steps
- Apply the vendor security update for Oracle E-Business Suite as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-56164 – Microsoft SharePoint Server ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS22% · P97
ActionPatch immediately
AffectedGovernment Transportation
Remediation Steps
- Apply the vendor security update for Microsoft Sharepoint Server as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-48939 – Joomlic Icagenda ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS83% · P100
ActionPatch immediately
Remediation Steps
- Check CISA Known Exploited Vulnerabilities Catalog for iCagenda advisory
- Apply vendor patch for unrestricted file upload vulnerability
- Review upload directories for any suspicious or unexpected files
- Restrict file upload functionality to authenticated users with appropriate permissions
References:
🛡️CVE-2026-48908 – JoomShaper SP Page Builder ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS88% · P100
ActionPatch immediately
Remediation Steps
- Check CISA Known Exploited Vulnerabilities Catalog for JoomShaper advisory and patch details
- Apply vendor patch for unrestricted file upload vulnerability
- Audit filesystem for unauthorized files or modifications
- Implement upload restrictions and validate file types server-side
References:
🛡️CVE-2026-56291 – Balbooa Forms ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS76% · P99
ActionPatch immediately
Remediation Steps
- Apply the vendor security update for Balbooa Forms as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-56290 – Joomlack Page Builder ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS83% · P100
ActionPatch immediately
Remediation Steps
- Apply the vendor security update for Joomlack Page Builder as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-58644 – Microsoft SharePoint ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS6% · P93
ActionPatch immediately
Remediation Steps
- Apply the vendor security update for Microsoft SharePoint as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-16232 – Check Point SmartConsole ✓ NVD
CVSS9.1 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS71% · P99
ActionPatch immediately
AffectedTechnology Finance
Remediation Steps
- Apply the vendor security update for Checkpoint Multi-Domain Security Management as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-55255 – Langflow ✓ NVD
CVSS8.4 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS29% · P98
ActionPatch immediately
Remediation Steps
- Apply the vendor security update for Langflow Langflow as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-18577 – N-Able N-Central ✓ NVD
CVSS8.1 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ● New this week ★ Added to KEV this week
EPSS4% · P90
ActionPatch immediately
AffectedGovernment Technology
Remediation Steps
- Apply the vendor security update for N-Able N-Central as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2021-27137 – Dd-Wrt ✓ NVD
CVSS8.1 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS16% · P97
ActionPatch immediately
Remediation Steps
- Apply the vendor security update for DD-WRT DD-WRT as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-56155 – Microsoft Active Directory Federation Services ✓ NVD
CVSS7.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS2% · P82
ActionPatch immediately
AffectedGovernment Transportation
Remediation Steps
- Apply the vendor security update for Microsoft Windows 10 1607 as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2023-4346 – KNX Association KNX Protocol Connection Authorization Option 1 ✓ NVD
CVSS7.5 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS1% · P57
ActionPatch immediately
Remediation Steps
- Apply the vendor security update for KNX Association KNX Protocol Connection Authorization Option 1 as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-18556 – N-Able N-Central ✓ NVD
CVSS7.4 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ● New this week ★ Added to KEV this week
EPSS<1% · P40
ActionPatch immediately
AffectedTechnology Government
Remediation Steps
- Apply the vendor security update for N-Able N-Central as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-15410 – SonicWall SMA1000 Appliances ✓ NVD
CVSS7.2 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS76% · P99
ActionPatch immediately
AffectedTechnology Finance
Remediation Steps
- Apply the vendor security update for SonicWall SMA1000 Appliances as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2025-68686 – Fortinet FortiOS ✓ NVD
CVSS5.9 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS1% · P67
ActionPatch immediately
AffectedTechnology
Remediation Steps
- Apply the vendor security update for Fortinet Fortios as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-60137 – WordPress Core ✓ NVD
CVSS5.9 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS73% · P99
ActionPatch immediately
AffectedGovernment Technology
Remediation Steps
- Apply the vendor security update for Wordpress as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-20316 – Cisco Secure Firewall Management Center (FMC) ✓ NVD
CVSS5.3 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS1% · P53
ActionPatch immediately
AffectedTechnology
Remediation Steps
- Apply the vendor security update for Cisco Secure Firewall Management Center as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2008-4128 – Cisco IOS ✓ NVD
CVSS4.3 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS33% · P98
ActionPatch immediately
AffectedGovernment Energy
Remediation Steps
- Check CISA Known Exploited Vulnerabilities Catalog for Cisco advisory and patch information
- Apply vendor patch from Cisco Security Advisories
- Verify Cisco IOS version after patching
- Monitor for signs of unauthorized access or configuration changes on affected devices
References:
🛡️CVE-2026-48449 – Adobe Campaign Classic ✓ NVD
CVSS10 NVD 3.1
Triage statusNo Known Exploit
ExploitationNo exploitation reported ● New this week
EPSS1% · P43
ActionPatch within 48 hours
AffectedFinance Technology
Remediation Steps
- Apply the vendor security update for Adobe Campaign Classic as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-64531 – Linux kernel Open vSwitch datapath ✓ NVD
CVSS7.8 NVD 3.1
Triage statusPoC Available
Exploitation🧪 PoC published
EPSS<1% · P3
ActionPatch within 48 hours
Remediation Steps
- Identify systems running Linux kernel with Open vSwitch enabled
- Apply available kernel security patches for the OVSwrap vulnerability
- Verify patch installation and reboot systems as required
- Monitor for indicators of exploitation (local privilege escalation attempts)
- Restrict local access on affected systems to minimize attack surface
References:
⏳Actionable · Partially verified
CVE in source articles · NVD enrichment pending⏳CVE-2026-58048 – cPanel pending NVD
CVSSawaiting NVD
Triage statusUnder Review
ExploitationNo exploitation reported
EPSS1% · P44
ActionPatch within 48 hours
Remediation Steps
- Apply the cPanel targeted security release addressing CVE-2026-58048
- Audit database access logs to identify unauthorized SQL execution in root context
- Review customer account activity for privilege escalation attempts
- Restrict customer-level database privileges to least-privilege model
References:
⏳CVE-2026-64638 – WordPress pending NVD
CVSSawaiting NVD
Triage statusUnder Review
ExploitationNo exploitation reported
EPSS1% · P52
ActionPatch this week
Remediation Steps
- Update WordPress to the latest patched version immediately
- Review administrator browsing activity and access logs for suspicious activity
- If administrators visited untrusted links, audit server-side code changes and logs
- Implement content security policy (CSP) headers to mitigate XSS impact
- Restrict administrative access to trusted networks where feasible
References:
🤖 This vulnerability report was compiled by defend.network using AI-powered analysis of vulnerability databases, vendor advisories, and threat intelligence feeds. Always verify remediation steps through official vendor channels before implementing changes in production environments.