← Back
VulnerabilitywatchTowr Labs·1 month ago

Enterprise Tech In, Shell Out (Progress Kemp LoadMaster Uninitialized Heap to Pre-Auth RCE CVE-2026-8037)

A critical pre-authentication remote code execution vulnerability in Progress Kemp LoadMaster, a widely deployed edge load balancer in enterprise networks, stems from an uninitialized heap condition that attackers can exploit to gain initial access. Given LoadMaster's common placement at network perimeters, successful exploitation could provide attackers with a direct entry point into enterprise environments. watchTowr Labs' analysis highlights how edge appliances, when compromised, can become attack vectors rather than security boundaries.

Read full article at watchTowr Labs

Related Articles

VulnerabilitySecurityWeek·2 days ago

Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini

Researchers have identified a new attack technique called Cryptographic Context Injection that encrypts malicious instructions to evade safety guardrails in AI models including Grok and Gemini. The method works by concealing harmful prompts until they are decrypted within a trusted execution environment, effectively bypassing existing content filtering mechanisms. This vulnerability highlights a novel attack vector against popular large language models that defenders should monitor.