TODAY
Progress LoadMaster under active attack — patch everything network-facing now.
THE THREE
- KEV#1 · CVE-2026-8037
Progress
What: If your organization uses Progress LoadMaster for load balancing, an unauthenticated attacker can run any command they want on the appliance — no login required — with a 99% exploit probability. This is a direct path to network takeover and ransomware deployment.
Why it moved: Actively exploited · Widely deployed · Critical severity · 99% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Apply the Progress LoadMaster patch immediately; isolate the appliance if patching is delayed.
- KEV#2 · CVE-2026-34486
Apache
What: Apache Tomcat is everywhere, and this flaw lets attackers bypass encryption protections — especially dangerous when chained with CVE-2025-24813, which can lead to remote code execution on your web servers. An 83% exploit probability means attackers are actively working this.
Why it moved: Actively exploited · Everyone runs this · 83% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Update Apache Tomcat to a patched version and verify EncryptInterceptor is correctly configured.
- KEV#3 · CVE-2026-10520
Ivanti
What: Ivanti Sentry has a perfect 10.0 CVSS score and near-certain exploit odds — a remote attacker with no credentials can gain full root control of the appliance, which typically sits at the edge of your mobile device management infrastructure. Compromise here means full visibility into managed devices.
Why it moved: Actively exploited · Widely deployed · Critical severity · 100% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Patch Ivanti Sentry immediately or take it offline until the update is applied.
TRAVERSAL
No cross-feed connection surfaced in today's graph. That's the honest reading — we don't invent one.
NUMBERS
- Entities
- 11M
- Relationships
- 65M
- Threat actors
- 356
- Indicators
- 560k
- Feeds live
- 0
- Sources total
- 21
Get tomorrow's brief in your inbox
07:15 UK. One email. One link. Nothing else.
Daily · one email · unsubscribe in one click · UK GDPR double opt-in.