Progress LoadMaster RCE Added to KEV; Microsoft Flaws Disclosed
Progress LoadMaster RCE added to KEV; multiple Microsoft privilege escalation flaws disclosed; WordPress plugins and other software also impacted.

Progress Kemp LoadMaster products are affected by a critical OS command injection vulnerability, CVE-2026-8037, which has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. This flaw allows unauthenticated attackers to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple API endpoints. The vulnerability has seen significant exploit attempts, with reports indicating over 792 attempts. Progress has released patches, and users are urged to update to the latest versions to mitigate the risk of compromise. The Hacker News reported on the active exploitation of this flaw.
A wave of critical vulnerabilities impacting Microsoft products has been disclosed, with several allowing for privilege escalation over a network. These include missing authorization or authentication flaws in Microsoft Teams (CVE-2026-65667), Azure SQL Database (CVE-2026-56162), Azure Key Vault (CVE-2026-62825), Azure DNS (CVE-2026-58275), Azure SRE Agent (CVE-2026-62830), Microsoft 365 Admin Center (CVE-2026-62873), and Azure Active Directory (CVE-2026-50481). Additionally, deserialization of untrusted data in Azure Service Bus (CVE-2026-50515) and improper handling of path parameters in Microsoft Entra Provisioning Service (CVE-2026-59115) also present significant risks. SecurityWeek noted these critical updates from Microsoft.
Several WordPress plugins are facing critical vulnerabilities, including authorization bypass in the AI Copilot – Content Generator plugin (CVE-2026-14526) and PHP Object Injection in the Ajax Search Lite plugin (CVE-2026-16258). The WP Events Manager plugin (CVE-2026-14205) has a vulnerability allowing authenticated users to create free events by manipulating quantity calculations. Separately, Plesk versions before 18.0.80 have an improper privilege management flaw in their XML-RPC API (CVE-2026-64637) that could allow a reseller to gain administrative access.
Critical vulnerabilities have also been identified in other software. Fanwei Weaver E-cology 9.0 (prior to 10.52) suffers from a file upload vulnerability (CVE-2022-4995) enabling unauthenticated attackers to upload arbitrary files. Flowise through version 3.1.4 contains an Insecure Direct Object Reference (IDOR) vulnerability in its OpenAI Assistants integration (CVE-2026-67622), allowing authenticated users to access other workspaces' credentials. Additionally, DataLinkDC's Dinky (CVE-2026-70558) has a path traversal vulnerability in its file upload handler, and WGDashboard versions 4.3.2 and earlier have a Server-Side Template Injection (SSTI) flaw (CVE-2026-15734) allowing authenticated attackers to execute arbitrary code. Vypr Intelligence highlighted the Flowise IDOR vulnerability.