Progress LoadMaster CVE-2026-8037: 792 Attacks Logged

Progress LoadMaster CVE-2026-8037 (CVSS 9.6) is on CISA's KEV list after 792 exploit attempts. Unauthenticated root RCE — patch now.

Progress LoadMaster CVE-2026-8037, a CVSS 9.6 unauthenticated command-injection flaw, has already been hit with 792 confirmed exploitation attempts from 65 IP addresses over 41 days — and CISA added it to its Known Exploited Vulnerabilities catalog on August 7. If your load balancer is still running an unpatched build, the scanning has almost certainly already…

Read More

VMware vCenter CVE-2026-59310: Germany Hit Hardest

VMware vCenter CVE-2026-59310, a CVSS 9.8 flaw, is under active exploitation in 47 countries — Germany is hit hardest. What to do now.

VMware vCenter CVE-2026-59310, a maximum-severity path-traversal vulnerability scoring 9.8 on CVSS, is being actively exploited across 47 countries — and Germany is the single most-affected country of all of them. German incident-response firm QUIRSO uncovered the campaign live during an IR engagement, tracing 361 distinct victim IP addresses back to a directory-traversal flaw in vCenter’s…

Read More

SAP Commerce Cloud CVE-2026-58231: CVSS 10.0 RCE

SAP Commerce Cloud CVE-2026-58231 (CVSS 10.0) lets unauthenticated attackers hit the Data Hub import endpoint for code execution. Patch and mitigation steps.

SAP Commerce Cloud CVE-2026-58231, a maximum-severity (CVSS 10.0) flaw disclosed on SAP’s August 2026 Security Patch Day, lets an unauthenticated attacker with network access reach the Data Hub import endpoint and potentially execute arbitrary code — no login, no user interaction, just a crafted request to a component many DACH e-commerce and manufacturing storefronts run…

Read More

CVE-2026-68820 WinSock Zero-Day: Lazarus Deploys Rootkit

CVE-2026-68820 WinSock zero-day

The CVE-2026-68820 WinSock zero-day was already being used by North Korea’s Lazarus Group to plant a kernel-mode rootkit weeks before Microsoft shipped a fix in its August 2026 Patch Tuesday. Any Windows endpoint that processes network sockets — which is to say, essentially every Windows machine on your network — was exposed until this month’s…

Read More

Metabase CVSS 10 SQL Injection Zero-Day Hits Admin Access

The Metabase CVSS 10 SQL injection zero-day gives attackers admin access and every connected database credential. Framework and Tally already hit.

The Metabase CVSS 10 SQL injection zero-day lets an unauthenticated attacker turn a self-hosted analytics dashboard into a master key for every database it touches. Active exploitation began August 3, 2026, and two named victims — Framework and Tally — have already confirmed customer data theft. If your organization runs Metabase for internal reporting, this…

Read More