Security advisories

Progress Kemp LoadMaster Vulnerability Targeted (CVE-2026-8037)

June 30, 2026

3 MINS READ

THE THREAT

Beginning on June 29th, 2026, eSentire’s Threat Response Unit (TRU) identified exploitation attempts targeting the critical Progress Kemp LoadMaster vulnerability CVE-2026-8037. The vulnerability was initially disclosed on June 4th and functional Proof-of-Concept (PoC) exploit code was released on June 29th. CVE-2026-8037 (CVSS: 9.8), is an OS Command Injection Remote Code Execution (RCE) vulnerability which allows an unauthenticated attacker to execute arbitrary commands on the LoadMaster appliance.  

As active exploitation attempts have been identified, it is critical that organizations apply the relevant security patches immediately.

What we’re doing about it 

What you should do about it 

Additional information

The vulnerability originates from improper handling of user-supplied input within the escape_quotes() function. The vulnerable code allocates heap buffer using malloc() and fails to properly null-terminate escaped strings. This condition allows out-of-bounds reads into adjacent heap memory, which can be manipulated by an attacker to introduce command injection content into a shell command that is executed via the system() function. 

watchTowr Labs demonstrates how specially crafted requests can leverage heap memory manipulation and command injection techniques to achieve RCE without authentication. The vulnerability is reachable through the /accessv2 endpoint when the API is enabled.
 
The impact of successful exploitation is severe. An unauthenticated attacker may be able to execute arbitrary commands on the affected appliance without possessing valid credentials. Because LoadMaster appliances are frequently positioned at the network edge and often have visibility into critical internal services, compromise of the device could facilitate initial access and further malicious activity within the environment.

In cases observed by eSentire, exploitation was not successful, and as such, no post-compromise activity was observed. Due to the availability of PoC exploit code and the potential value for initial access, the eSentire Threat Intelligence team assesses that it is highly probably exploitation attempts targeting CVE-2026-8037 will increase in the immediate future.

Affected Products
Product Name Affected Version(s) Resolved Version(s)
Progress Kemp LoadMaster (GA) 7.2.63.1 and prior 7.2.63.2
Progress Kemp LoadMaster (LTSF) 7.2.54.17 and prior 7.2.54.18
Indicators of Compromise (IOCs)
192[.]42[.]116[.]58 Attacker IPs
192[.]42[.]116[.]105
146[.]70[.]139[.]154

References: 

[1]  https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691  

[2] https://labs.watchtowr.com/enterprise-tech-in-shell-out-progress-kemp-loadmaster-uninitialized-heap-to-pre-auth-rce-cve-2026-8037/  

[3] https://www.zerodayinitiative.com/advisories/ZDI-26-342/  

 

Back to Security Advisories

Speak With A Security Expert Now

TALK TO AN EXPERT
View Most Recent Advisories