Progress LoadMaster flaw lets attackers run commands without login
| 5 added to KEV |
0 used in ransomware |
2026-08-07 nearest federal deadline |
This week, 5 exploited vulnerabilities were added to the federal patching deadline list. One bypasses authentication entirely. The nearest due date has already passed.
The Showcase Vulnerability
CVE-2026-8037: Progress LoadMaster Command Injection
Progress LoadMaster contains a command injection vulnerability in multiple command endpoints. An unauthenticated attacker can send unsanitized input to execute arbitrary commands directly on the LoadMaster appliance. No login required. No interaction needed.
Required action: Apply mitigations in accordance with vendor instructions. Evaluate your LoadMaster's internet exposure. If mitigations are unavailable, discontinue use of the product.
Due date: August 10, 2026 (this Saturday).
4 Other Exploited Vulnerabilities Added This Week
- JetBrains TeamCity Deserialization of Untrusted Data Vulnerability
- N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
- IBM Langflow Code Injection Vulnerability
The question now is: which of these five actually run in your environment, and which one poses the highest risk to you first?
Struggling to patch before the deadline? We'll do this week's triage for you. Free.
Tell us what you run — we'll send back which of the currently-exploited vulnerabilities actually hit your stack, the order to fix them in, and what you can ignore. A person writes it, not a script. No call, no access to your systems.
Before you go — here's the 30-second version for your stack.
Everything CISA flagged this week fell into just a few buckets: 2 enterprise apps (Progress, IBM), 2 other (JetBrains, N-able) and 1 Linux & open source (Apache).
So if you don't run enterprise apps or other or Linux & open source, this week is a no-op for you. Close this email and get on with your day — nothing here is yours. If you do run one of them, the deadline is 2026-08-10.
That paragraph you just read — "this week is a no-op for you" — is the entire product. Most weeks, most of the catalog isn't yours. Knowing which part is, in 30 seconds, without reading a vulnerability database, is what you're actually short of.
ClickSecurity Pro does it precisely instead of roughly: you tell us your stack once, and each week you get only what touches your gear — ranked by what to fix first, with the fixed version and the federal deadline. No triage, no catalog, no guessing.
Filter next week to my stack — $5/mo
Not ready? Tell us what you run and we'll at least stop sending you things that aren't yours.