CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Progress Kemp LoadMaster Pre-Auth Root Command Injection Flaw (CVE-2026-8037) Patched

June 30, 2026

A critical vulnerability in Progress Kemp LoadMaster, tracked as CVE-2026-8037 with a CVSS score of 9.8, allows unauthenticated attackers to execute arbitrary commands as root on the appliance. The flaw resides in the escape_quotes() function, which fails to null-terminate sanitized input, enabling memory corruption and command injection via crafted API requests to the /accessv2 endpoint.

Affected versions include LoadMaster GA v7.2.63.1 and older, and LTSF v7.2.54.17 and older, when the API is enabled. Progress released fixed versions GA v7.2.63.2 and LTSF v7.2.54.18. The vulnerability was discovered by Syed Ibrahim Ahmed of TrendAI Research and reported through the Zero Day Initiative. watchTowr Labs published a full technical breakdown with a working proof of concept on June 29, 2026.

Progress also patched a second high-severity flaw, CVE-2026-33691, a WAF bypass via whitespace padding in filenames. This is not LoadMaster’s first critical issue; CVE-2024-1212 (CVSS 10.0) was previously exploited in the wild and added to CISA’s Known Exploited Vulnerabilities catalog. The Canadian Centre for Cyber Security has urged administrators to apply updates.

CVEs: CVE-2026-8037, CVE-2026-33691, CVE-2024-1212, CVE-2026-20245

Attack groups: Cl0p

Companies: Progress Software, TrendAI Research, Zero Day Initiative, watchTowr Labs, Canadian Centre for Cyber Security

Products: Kemp LoadMaster, MOVEit