A load balancer's input-sanitising function is the reason it can be owned without a password
2026-08-10Security
CVE-2026-8037 is a CVSS 9.6 command injection in Progress Kemp LoadMaster, traced to its escape_quotes() routine. 792 exploitation attempts over 41 days from 65 IPs across 18 countries — and the federal remediation deadline is today.