piyokango[verified]@piyokangoActive Exploitation
CVE‑2026‑8037 is a critical OS command injection in Progress LoadMaster products, actively exploited in the wild with PoC and exploit code available, and patches have been released; CISA has catalogued it as a known exploited vulnerability.
ThreatCluster[verified]@threatclusterPatch
The text reports that Progress released a LoadMaster security bulletin addressing two vulnerabilities (CVE-2026-8037 and CVE-2026-33691) disclosed in June 2026, with no indication of exploitation or artifact details.
Open Source Security mailing list@oss_securityDisclosure
CVE-2026-33691 is a disclosed OWASP CRS vulnerability that uses whitespace padding to bypass file upload extension checks, enabling dangerous uploads on Windows. No PoC, exploit code, patch, or evidence of active exploitation is provided.
Core Rule Set@CoreRuleSetPatch
The advisory exposes a file‑upload bypass in OWASP CRS using whitespace padding, recommends upgrading to specific CRS versions for mitigation, and provides no evidence of exploitation or exploit code.
cPanel@cPanelPatch
The tweet announces a new EasyApache 4 release that patches several CVEs by upgrading components such as Tomcat, re2c, rack, and OWASP CRS, and links to the full changelog.
CERT-PY@CERTpyGeneral
The tweet announces two CVEs affecting Progress products and links to an external source for additional information, but does not provide PoC, exploit details, patch information, or technical specifics.
CERT-PY@CERTpyDisclosure
The post announces two new CVEs (CVE‑2026‑8037 and CVE‑2026‑33691) affecting Progress products and directs readers to external links for more information.
Open Source Security mailing list@oss_securityDisclosure
The post announces that CVE-2026-33691, an OWASP CRS whitespace padding bypass vulnerability, also affects Linux in addition to Windows.