Critical CVEs CVE-2026-33691: Progress Kemp LoadMaster WAF Bypass via Whitespace Padding June 30, 2026 ♡Follow0 A high-severity flaw in Progress Kemp LoadMaster allows WAF bypass by using whitespace padding in filenames to circumvent file upload extension checks. Discovered from: Progress Kemp LoadMaster Pre-Auth Root Command Injection Flaw (CVE-2026-8037) Patched CVE-2026-33691file uploadProgress Kemp LoadMasterWAF bypass