June 30, 2026
- watchTowr published a deep-dive on CVE-2026-8037, an uninitialized-heap bug in Progress Kemp LoadMaster that escalates to unauthenticated pre-auth RCE on an appliance that typically sits at the network edge. Classic "the way in rather than the thing keeping people out" exposure for anyone fronting services with LoadMaster. watchTowr Labs · Vulnerabilities & Exploits