{"id":23162,"date":"2026-08-09T09:00:00","date_gmt":"2026-08-09T09:00:00","guid":{"rendered":"https:\/\/www.securitytoday.de\/?p=23162"},"modified":"2026-10-01T15:43:52","modified_gmt":"2026-10-01T15:43:52","slug":"loadmaster-in-the-kev-list-patch-has-been-available-since-june","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2026\/08\/09\/loadmaster-in-the-kev-list-patch-has-been-available-since-june\/","title":{"rendered":"LoadMaster in the KEV List: Patch Has Been Available Since June"},"content":{"rendered":"<p style=\"color:#69d8ed;font-size:0.9em;margin:0 0 16px;padding:0;\">8 min read<\/p>\n<p><strong>On 7 August 2026, CISA added CVE-2026-8037 to the Known Exploited Vulnerabilities Catalog-exactly one new entry that day. The Progress Kemp LoadMaster command-injection flaw has been patched since June 2026, yet a public exploit has existed since 29 June. The open question is why prioritisation kept this gap open for so long.<\/strong><\/p>\n<div style=\"background:#003340;color:#fff;padding:32px 36px;margin:32px 0;border-radius:8px;\">\n<p style=\"color:#69d8ed;text-transform:uppercase;letter-spacing:0.08em;font-size:0.82em;font-weight:700;margin:0 0 16px;\">Key Takeaways<\/p>\n<ul style=\"margin:0;padding-left:20px;line-height:1.7;\">\n<li><strong style=\"color:#69d8ed;\">KEV on 7 Aug:<\/strong> CVE-2026-8037 was the only new entry that day. The remediation deadline 10 August 2026 applies to U.S. federal agencies under BOD 26-04 and serves in the DACH region as an urgency signal without its own legal obligation.<\/li>\n<li><strong style=\"color:#69d8ed;\">Exploitation attempts:<\/strong> KEVIntel logged 792 exploitation attempts in 41 days from 65 IP addresses across 18 countries. eSentire observed attempts from 29 June 2026 onward. In all observed cases exploitation failed and no post-compromise activity occurred.<\/li>\n<li><strong style=\"color:#69d8ed;\">Patch available since June:<\/strong> Affected versions are Progress Kemp LoadMaster GA up to 7.2.63.1 and LTSF up to 7.2.54.17. Fixed builds are 7.2.63.2 and 7.2.54.18. The unauthenticated attack path via \/accessv2 leads, if successful, to root privileges.<\/li>\n<li><strong style=\"color:#69d8ed;\">Ransomware status:<\/strong> CISA rates knownRansomwareCampaignUse for this entry as Unknown-no statement that ransomware exploitation is ruled out.<\/li>\n<\/ul>\n<\/div>\n<p style=\"border-top:1px solid rgba(230,227,218,0.14);border-bottom:1px solid rgba(230,227,218,0.14);padding:14px 0;margin:28px 0;font-size:0.92em;color:#b8c5ce;\"><strong style=\"color:#69d8ed;\">Related:<\/strong> BOD 26-04: Prioritising KEV and EPSS the right way &nbsp;\u00b7&nbsp; <a href=\"https:\/\/www.securitytoday.de\/en\/2026\/07\/26\/windows-vulnerabilities-patch-priority-critical-assets\/\">Windows vulnerabilities: Patch order for critical assets<\/a><\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">What the 7 August KEV inclusion signals<\/h2>\n<p><strong>What is the KEV catalog?<\/strong> The CISA Known Exploited Vulnerabilities Catalog lists flaws with confirmed active exploitation. U.S. federal agencies must remediate entries within the stated deadlines under Binding Operational Directive 26-04. For organisations and agencies in the DACH region, the catalog carries no legal obligation of its own; instead it functions as a prioritised urgency signal backed by robust telemetry and official assessment.<\/p>\n<p>On 7 August 2026 CISA added exactly one new entry to the KEV catalog: CVE-2026-8037, described as the Progress LoadMaster Command Injection Vulnerability. The due date in the entry is 2026-08-10-just three days after inclusion. For U.S. federal agencies this is a binding requirement under BOD 26-04; for German, Austrian and Swiss organisations it is a prioritised warning without legal force.<\/p>\n<p>The Canadian Centre for Cyber Security appended its Advisory AV26-552 on the same day to include the KEV entry. The parallel update shows that multiple authorities reached the same escalation threshold. CISA simultaneously rates knownRansomwareCampaignUse for this entry as Unknown-meaning the field cannot be shortened to \u201cno ransomware.\u201d<\/p>\n<p>The real finding for internal governance lies in the gap: the vendor patch has been available since 4 June 2026, the public proof-of-concept since 29 June 2026, yet the KEV inclusion only arrived on 7 August. Teams that schedule patches solely by CVSS scores and release windows detect this lag too late; teams that weigh exploitability and exposure earlier would already have moved this gap to the top of the queue in June.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">The Technical Attack Path on LoadMaster<\/h2>\n<p>CVE-2026-8037 allows an unauthenticated attacker to execute arbitrary commands on the LoadMaster appliance via unsanitized input across multiple command endpoints. The path runs through the API endpoint \/accessv2, provided the API is enabled. The root cause lies in the function escape_quotes(). It lacks null termination, resulting in a heap out-of-bounds read. This chain is described by eSentire with technical details from watchTowr Labs.<\/p>\n<div data-element=\"definition_box\" style=\"background:#23261f;border:1px solid rgba(105,216,237,0.22);border-radius:10px;padding:20px 24px;margin:32px 0;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 2px 10px rgba(0,0,0,0.22);\">\n<p style=\"margin:0 0 8px;font-family:'IBM Plex Mono',ui-monospace,SFMono-Regular,monospace;font-size:0.72em;letter-spacing:0.12em;text-transform:uppercase;color:#69d8ed;\">Definition &middot; Pre-Auth RCE<\/p>\n<p style=\"margin:0;color:#e6e3da;line-height:1.6;\">A remote code execution vulnerability that does not require prior authentication. The attacker needs no valid credentials and can directly coerce the appliance into executing arbitrary commands. In the case of CVE-2026-8037, these commands run with root privileges.<\/p>\n<\/div>\n<p>If successfully exploited, the injected commands run as root. Valid credentials are not required. LoadMaster typically sits in front of sensitive services and controls traffic. A root shell on the appliance is therefore not an isolated host issue-it opens the door to downstream systems and configurations that govern production traffic.<\/p>\n<p>Affected versions include Progress Kemp LoadMaster GA up to and including 7.2.63.1 and LTSF up to and including 7.2.54.17. Fixed versions are 7.2.63.2 and 7.2.54.18, respectively. This version range is drawn from eSentire\u2019s table based on vendor status as of 30 June 2026 and is confirmed by AV26-552 from the Canadian Centre for Cyber Security. Organizations that maintain asset inventories without build numbers or API flags cannot reliably scope the affected population.<\/p>\n<p>Severity assessments diverge noticeably. Media coverage and eSentire assign a CVSS score of 9.6, while the Zero Day Initiative rates the same CVE (ZDI-26-342) at 9.8. Both values indicate critical impact. The discrepancy belongs in the decision file, but it does not replace the need to verify whether the API is reachable and whether the patch level is correct.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">Timeline: From Disclosure to Regulatory Deadline<\/h2>\n<p>The Zero Day Initiative reported the vulnerability to Progress on 15 April 2026. On 4 June 2026, the vendor issued its bulletin and CVE disclosure. A functional proof-of-concept emerged on 29 June 2026, and eSentire observed exploitation attempts from that same day. On 7 August 2026, CISA added the CVE to its Known Exploited Vulnerabilities (KEV) catalog, giving U.S. federal agencies until 10 August 2026 to remediate.<\/p>\n<p>The gap between disclosure and KEV entry is roughly two months; the gap between public exploit and KEV entry is just under six weeks. During this window, both the patch and the attack path were public. Organizations that treat KEV as their primary trigger act only when CISA adds the entry. Those that also monitor vendor fixes and proof-of-concept publications prioritized this CVE back in June.<\/p>\n<p>The three-day deadline after KEV inclusion underscores how CISA evaluates risk for its own scope. It intensifies the expectation of immediate remediation. For DACH stakeholders, the deadline remains a benchmark for urgency, but it does not create a domestic regulatory deadline. Relying on it alone imports U.S. federal logic and overlooks the earlier window for action.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">Telemetry: 792 Attempts and What They Don\u2019t Prove<\/h2>\n<p>KEVIntel reports 792 exploitation attempts over 41 days from 65 unique IP addresses across 18 countries. Among the locations mentioned are Australia, China, Indonesia, Japan, Poland, and the USA. The most recent recorded activity occurred on 4 August 2026, with five attempts. These figures describe scanning and exploit attempts. They do not confirm any successful compromises.<\/p>\n<div data-element=\"stat_row\" style=\"display:flex;flex-wrap:wrap;gap:16px;margin:32px 0;\">\n<div style=\"flex:1 1 200px;min-width:0;background:#003340;border:1px solid rgba(105,216,237,0.28);border-radius:10px;padding:22px 20px;box-sizing:border-box;\">\n<div style=\"font-size:2.1em;font-weight:800;color:#69d8ed;line-height:1.1;word-break:keep-all;\">792<\/div>\n<p style=\"margin:10px 0 0;font-size:0.88em;color:#e6e3da;line-height:1.5;\">Exploitation attempts in 41 days (KEVIntel via The Hacker News, 08.08.2026)<\/p>\n<\/div>\n<div style=\"flex:1 1 200px;min-width:0;background:#003340;border:1px solid rgba(105,216,237,0.28);border-radius:10px;padding:22px 20px;box-sizing:border-box;\">\n<div style=\"font-size:2.1em;font-weight:800;color:#69d8ed;line-height:1.1;word-break:keep-all;\">65<\/div>\n<p style=\"margin:10px 0 0;font-size:0.88em;color:#e6e3da;line-height:1.5;\">Unique source IPs from 18 countries (KEVIntel, 08.08.2026)<\/p>\n<\/div>\n<div style=\"flex:1 1 200px;min-width:0;background:#003340;border:1px solid rgba(105,216,237,0.28);border-radius:10px;padding:22px 20px;box-sizing:border-box;\">\n<div style=\"font-size:1.4em;font-weight:800;color:#69d8ed;line-height:1.1;word-break:keep-all;\">10 August 2026<\/div>\n<p style=\"margin:10px 0 0;font-size:0.88em;color:#e6e3da;line-height:1.5;\">Deadline for US federal agencies per KEV entry (CISA)<\/p>\n<\/div>\n<\/div>\n<p>eSentire observed exploitation attempts beginning on 29 June 2026, the day the Proof-of-Concept was published. In the cases monitored by eSentire, exploitation was unsuccessful. There was no post-compromise activity. This limitation must accompany every reference to the 792 attempts. Anyone interpreting the figure as evidence of widespread takeovers is straying from the source material.<\/p>\n<p>For the SOC, this leads to a clear distinction. Telemetry on attempts justifies heightened detection and accelerated patching. It does not replace forensic confirmation of a breach. At the same time, the current lack of success in eSentire\u2019s cases does not permanently ease the risk assessment. The unauthenticated path remains and, if exploited successfully, ends in root access. A later successful attempt would abruptly change the situation.<\/p>\n<p>CISA maintains the knownRansomwareCampaignUse status as Unknown. The strict reading applies here as well. Unknown does not mean disproven. It means the agency has not documented any reliable attribution to ransomware campaigns. Incident-response plans should therefore continue to model LoadMaster compromises with lateral movement and data exfiltration. A ransomware angle should neither be assumed nor ruled out.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">What the Delay Reveals About Your Own Prioritization<\/h2>\n<p>Case CVE-2026-8037 exposes control gaps that are structurally embedded in many patch programs. A vulnerability allowing unauthenticated root execution on a load balancer carries high asset criticality. The patch was available early. The public exploit carried a clear timestamp. Yet for many organizations, it is only the KEV listing that marks the moment they treat the issue as \u201ctruly urgent.\u201d<\/p>\n<p>Three typical mechanisms explain this pattern. First: prioritization based solely on CVSS without exposure context. Scores of 9.6 and 9.8 signal severity but say nothing about the reachability of \/accessv2 within your own network. Second: reliance on government catalogs as the starting gun. KEV is a strong signal, but it arrives after attackers have already begun testing the PoC. Third: incomplete inventories of appliance builds and API status. Without these attributes, the vulnerability remains invisible in the queue.<\/p>\n<p>The delay in public escalation is therefore not an argument against KEV. It is an argument for an internal early phase. Vendor bulletins, CVE disclosures, and public Proofs-of-Concept are independent triggers. Combining them with asset class and internet exposure moves LoadMaster fixes ahead of the KEV line. Waiting buys time for attackers and squanders control time in the change window.<\/p>\n<p>For senior leadership, a concise review suffices. When did the patch enter release? When was the estate inventoried for build level and API flag? When did rollout begin? If the start date is after 7 August, the program is being steered too heavily by external catalogs. If the start date is already in June, the organization has productively used the interval between patch availability and KEV listing.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">Action Framework for DACH Decision-makers<\/h2>\n<p>First, take stock of your environment. All Progress Kemp LoadMaster instances must be checked against GA 7.2.63.2 and LTSF 7.2.54.18. At the same time, verify the API status and reachability of \/accessv2 from untrusted networks. Systems below the specified maximum versions must be patched. Systems with unnecessary API exposure require a hardening decision, even after the fix.<\/p>\n<div data-element=\"checklist\" style=\"background:#23261f;border:1px solid rgba(105,216,237,0.22);border-radius:10px;padding:22px 24px;margin:32px 0;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 2px 10px rgba(0,0,0,0.22);\">\n<p style=\"margin:0 0 12px;font-family:'IBM Plex Mono',ui-monospace,SFMono-Regular,monospace;font-size:0.72em;letter-spacing:0.12em;text-transform:uppercase;color:#69d8ed;\">Immediate LoadMaster Check<\/p>\n<ul style=\"margin:0;padding-left:0;list-style:none;\">\n<li style=\"margin:0 0 10px;padding-left:26px;position:relative;color:#e6e3da;line-height:1.5;\"><span style=\"position:absolute;left:0;color:#69d8ed;\">&#10003;<\/span>Determine version: GA up to 7.2.63.1 and LTSF up to 7.2.54.17 are affected.<\/li>\n<li style=\"margin:0 0 10px;padding-left:26px;position:relative;color:#e6e3da;line-height:1.5;\"><span style=\"position:absolute;left:0;color:#69d8ed;\">&#10003;<\/span>Patch to 7.2.63.2 or 7.2.54.18 respectively.<\/li>\n<li style=\"margin:0 0 10px;padding-left:26px;position:relative;color:#e6e3da;line-height:1.5;\"><span style=\"position:absolute;left:0;color:#69d8ed;\">&#10003;<\/span>Check if the API is active. The attack path runs via \/accessv2.<\/li>\n<li style=\"margin:0 0 10px;padding-left:26px;position:relative;color:#e6e3da;line-height:1.5;\"><span style=\"position:absolute;left:0;color:#69d8ed;\">&#10003;<\/span>Isolate the management interface from the internet until the patch is applied.<\/li>\n<li style=\"margin:0 0 10px;padding-left:26px;position:relative;color:#e6e3da;line-height:1.5;\"><span style=\"position:absolute;left:0;color:#69d8ed;\">&#10003;<\/span>Perform forensic triage on appliances exposed since 29 June.<\/li>\n<\/ul>\n<\/div>\n<p>Detection should incorporate the known attack patterns observed since 29 June 2026. The 792 recorded attempts and the five attempts on 4 August 2026 signal ongoing scanning activity. In eSentire\u2019s observations, exploitation remained unsuccessful and no post-compromise activity followed. Still, review logs for unusual API calls and unexpected process launches on the appliance.<\/p>\n<p>The US deadline of 10 August 2026 applies to US federal agencies under BOD 26-04. It carries no legal force in the DACH region. Yet it serves as a benchmark for how tightly CISA is constraining the remaining window of action. If you operate LoadMaster in the production path and have not yet rolled out the patch, you should impose the same internal urgency. The rationale is exposure and exploit posture-not the US directive itself.<\/p>\n<p>Finally, put your governance logic to the test. KEV entries remain required reading. They must not be the sole escalation lever for internet-facing appliances. Disclosure, vendor fixes, PoC evidence and telemetry on attempts need to trigger earlier. CVE-2026-8037 illustrates this sequence in stark relief: patch early, exploit public, exploitation attempts for weeks, KEV late, deadline tight, ransomware usage unknown.<\/p>\n<h2 style=\"padding-top:64px;margin-bottom:20px;\">Frequently Asked Questions<\/h2>\n<p class=\"st-faq-hint\">Each question is locked. Tap to unlock the answer.<\/p>\n<details>\n<summary><strong>Does the deadline 10 August 2026 also apply to German companies?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">No. The remediation deadline 2026-08-10 in the KEV entry applies to U.S. federal agencies under Binding Operational Directive 26-04. In the DACH region, it serves as an urgency signal without its own legal obligation. The operational consequence arises from exposure and exploitation status, not from the U.S. directive.<\/p>\n<\/details>\n<details>\n<summary><strong>Do the 792 recorded activities indicate successful attacks?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">No. KEVIntel counts 792 exploitation attempts over 41 days from 65 IP addresses across 18 countries. eSentire observed attempts starting 29 June 2026. In the cases monitored by eSentire, exploitation was unsuccessful and no post-compromise activity occurred. The figure describes attempts only. Documented compromises are not included.<\/p>\n<\/details>\n<details>\n<summary><strong>Which versions of Progress Kemp LoadMaster are affected?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Affected are GA versions up to and including 7.2.63.1 and LTSF versions up to and including 7.2.54.17. Fixed versions are 7.2.63.2 and 7.2.54.18 respectively. The attack path runs via \/accessv2 when the API is enabled. The root cause is escape_quotes() with missing null termination and a heap out-of-bounds read.<\/p>\n<\/details>\n<details>\n<summary><strong>What CVSS score applies to CVE-2026-8037?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Reporting and eSentire list the score as 9.6. The Zero Day Initiative rates the same CVE under ZDI-26-342 at 9.8. Both values stand side by side. The discrepancy is real and should remain visible in risk documentation.<\/p>\n<\/details>\n<details>\n<summary><strong>Is the vulnerability being exploited in ransomware campaigns?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">CISA classifies knownRansomwareCampaignUse for CVE-2026-8037 as Unknown. This is not a statement excluding ransomware exploitation. Shortening to \u201cno ransomware\u201d is impermissible. The assessment remains open until the agency issues a different classification.<\/p>\n<\/details>\n<p><!--ST-LOWER-CARDS lang=en--><\/p>\n<h3 style=\"margin:48px 0 18px;padding-left:12px;font-size:1.05em;font-weight:800;color:#e6e3da;border-left:3px solid #69d8ed;line-height:1.2;\">Editor&#8217;s Picks<\/h3>\n<p><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/07\/28\/cert-bund-revocates-zabbix-warning-after-24-hours\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/zabbix-xss-offen-monitoring-zugang-neu-absichern-cover-hero-1-250x141.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Reading Tip<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">CERT-Bund Reverses Zabbix Warning After 24 Hours<\/span><\/span><\/a><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/07\/27\/ffmpeg-everywhere-pixelsmash-forces-inventory-overhaul\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/pixelsmash-ffmpeg-inventur-upload-pfade-cover-hero-250x141.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Reading Tip<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">ffmpeg is Everywhere: PixelSmash Forces Inventory Check<\/span><\/span><\/a><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/08\/chaindrop-npm-wurm-trifft-keyv-und-cacheable-cover-hero-250x141.jpg\" alt=\"\" loading=\"lazy\" width=\"1116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Reading Tip<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">ChainDrop: npm Worm Targets keyv and cacheable<\/span><\/span><\/p>\n<h3 style=\"margin:48px 0 18px;padding-left:12px;font-size:1.05em;font-weight:800;color:#e6e3da;border-left:3px solid #69d8ed;line-height:1.2;\">More from the MBF Media Network<\/h3>\n<p><a href=\"https:\/\/www.cloudmagazin.com\/en\/2026\/08\/04\/downloadable-doesnt-mean-deployable\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/08\/net-herunterladbar-heisst-nicht-betreibbar-29798347.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#0bb7fd;margin-bottom:5px;\">cloudmagazin<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Downloadable Doesn&#8217;t Mean Deployable<\/span><\/span><\/a><a href=\"https:\/\/www.digital-chiefs.de\/en\/local-ai-governance-before-hardware-purchase\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/08\/net-local-ai-governance-vor-dem-hardwarekauf-32868665-250x141.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#e8828d;margin-bottom:5px;\">Digital Chiefs<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Local AI: Governance Before Hardware Purchase<\/span><\/span><\/a><\/p>\n<p style=\"font-style:italic;text-align:right;font-size:0.85em;color:#888;margin-top:8px;\">Image source: AI-generated (August 2026)<\/p>\n<p><!--\/ST-LOWER-CARDS--><\/p>\n","protected":false},"excerpt":{"rendered":"CVE-2026-8037 in Progress: Kemp LoadMaster has been listed in the KEV catalog since August 7th. The patch has been available since June 2026.","protected":false},"author":10,"featured_media":23096,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"But wait, that's not a German word; it's a CVE identifier. CVE stands for Common Vulnerabilities and Exposures, which is a system for class","_yoast_wpseo_title":"LoadMaster in the KEV List: Patch Has Been Available Since June","_yoast_wpseo_metadesc":"Progress Kemp LoadMaster vulnerability CVE-2026-8037 added to KEV catalog. Patch available since June. Learn what this means for your prioritization.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":0,"_evm_slot_owner":"","evm_cvss":0,"evm_risk":0,"evm_casefile":"","evm_primary_cve":"","evm_pin_until":0,"evm_external_preview_token":"","evm_external_preview_expires":"","_evm_translation_lang":"","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":[],"footnotes":""},"categories":[255],"tags":[],"class_list":["post-23162","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-praxis-umsetzung-en"],"evm_reading_time_minutes":12,"wpml_language":"en","wpml_translation_of":23094,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/23162","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=23162"}],"version-history":[{"count":2,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/23162\/revisions"}],"predecessor-version":[{"id":24407,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/23162\/revisions\/24407"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/23096"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=23162"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=23162"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=23162"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}