/00 — boot sequence

Hello.

Article

Kemp LoadMaster RCE: Pre-Auth Root Exploit Under Attack

July 12, 2026•7 min read
CVE-2026-8037 Kemp LoadMaster RCE Progress Software cybersecurity load balancer

A critical remote code execution vulnerability in Progress Kemp LoadMaster is under active exploitation, allowing unauthenticated attackers to execute arbitrary commands at the root level. Tracked as CVE-2026-8037, the flaw affects LoadMaster's API component and stems from an uninitialized heap memory bug in the command escaping logic. With proof-of-concept code publicly available and CISA tracking exploitation, organizations using Kemp LoadMaster need to act immediately.

Vulnerability Details

CVE-2026-8037 is an OS Command Injection vulnerability in the Kemp LoadMaster API that allows an unauthenticated attacker to execute arbitrary commands on the appliance. The vulnerability carries a CVSS v3.1 score of 9.6 (Critical) with the vector AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, indicating network-adjacent exploitable access, low attack complexity, no privileges required, no user interaction, and a scope change with high impact to confidentiality, integrity, and availability.

The root cause lies in the escape_quotes function within the LoadMaster binary. This function is responsible for sanitizing user-supplied input before inserting it into shell commands wrapped in single quotes. The implementation had two critical flaws: it allocated an uninitialized heap buffer using malloc() instead of calloc(), and it failed to null-terminate the escaped output string. When user input contained a single quote, the function allocated a new buffer and copied the escaped representation character by character, but omitted the null terminator at the end. The patched version fixes this by using calloc() (which zero-fills the buffer) and explicitly writing a null terminator after the escaped output.

What makes this vulnerability particularly dangerous is that it does not require authentication. Any attacker who can reach the LoadMaster management API can exploit it. The function is used across multiple command endpoints, giving attackers broad opportunities for injection.

Affected Systems

The vulnerability affects the following Progress products:

ProductAffected VersionsFixed Version
Kemp LoadMaster GAv7.2.63.1 and olderv7.2.63.2
Kemp LoadMaster LTSFv7.2.54.17 and olderv7.2.54.18
ECS Connections Managerv7.2.60.0 to v7.2.63.1v7.2.63.2
Object Scale Connection Managerv7.2.60.0 to v7.2.63.1v7.2.63.2
MOVEit WAFv7.2.60.0 to v7.2.63.1v7.2.63.2

The API must be enabled for the vulnerability to be exploitable. Given that LoadMaster is typically deployed as an edge load balancer with its management interface accessible over the network, this configuration is common in enterprise environments.

Impact Assessment

A successful exploit gives an attacker complete control over the LoadMaster appliance at the root level. From there, they can:

  • Pivot deeper into the network: LoadBalancers sit at the network edge and have visibility into internal routing, making them ideal beachheads.
  • Intercept or redirect traffic: With root access to a load balancer, attackers can modify traffic rules, intercept SSL/TLS connections, or redirect users to malicious destinations.
  • Extract credentials: LoadMaster appliances often store SSL certificate private keys, API credentials, and other sensitive data.
  • Deploy persistence: Root access enables installing backdoors, kernel modules, or rootkits that survive reboots.
  • Lateral movement: The appliance's network position makes it a launch point for attacks against backend servers.

Given Progress Software's history (the company behind the MOVEit Transfer breach that affected thousands of organizations worldwide), security teams should treat this vulnerability with extreme urgency.

Technical Analysis

The watchTowr Labs team published a detailed technical analysis of CVE-2026-8037, revealing the exploit mechanism. The vulnerable escape_quotes function processes user input intended for single-quoted shell arguments. When the input contains a single quote character, the function allocates a new heap buffer:

c

It then walks the input character by character. Normal characters are copied verbatim, while each single quote is expanded into the four-byte sequence '\'' (close quote, escaped quote, reopen quote). However, the function never writes a null terminator after the last character, leaving the heap buffer unterminated.

The patched version uses calloc() and adds an explicit null terminator:

c

The missing null terminator means that when the escaped string is later used in a shell command, the operating system reads past the allocated buffer into adjacent heap memory. An attacker who can control what data sits adjacent in the heap can inject arbitrary shell commands that execute with root privileges. This is a classic uninitialized heap memory exploitation pattern that skilled attackers can reliably weaponize.

Active Exploitation

Multiple security vendors have confirmed active exploitation attempts in the wild. The Hacker News reported on July 10, 2026, that attackers are actively scanning for and targeting vulnerable LoadMaster instances. SC Media also confirmed active exploitation. CISA's ADP assessment tags the vulnerability with "exploitation: poc" and "technicalImpact: total", confirming that proof-of-concept code exists and successful exploitation leads to total technical impact.

The vulnerability was discovered by Syed Ibrahim Ahmed of TrendAI Research, who reported it through Progress's disclosure program. watchTowr Labs independently identified the same flaw through their routine diffing process and published a comprehensive technical analysis including exploit methodology.

Detection

Organizations can detect exploitation attempts by monitoring LoadMaster API access logs for unusual patterns, particularly:

  • Requests containing single quote characters or shell metacharacters in API parameters
  • API calls to the apiuser endpoint with crafted payloads
  • Unexpected process creation or network connections originating from the LoadMaster appliance
  • File modifications in system directories
  • Unusual outbound connections from the management interface

Security teams should also check for the presence of the indicator artifacts described in CISA and vendor advisories.

Mitigation and Patching

Progress has released patches for all affected product lines:

ProductFixed VersionRelease Date
Kemp LoadMaster GAv7.2.63.2June 2026
Kemp LoadMaster LTSFv7.2.54.18June 2026

Immediate steps:

  1. Upgrade to the patched version immediately. There are no known workarounds that fully mitigate this vulnerability.
  2. If immediate patching is not possible, restrict network access to the LoadMaster management interface to trusted IP addresses only.
  3. Disable the API if it is not required for operations.
  4. Review the vendor security bulletin at the Progress community site for additional guidance.
  5. Monitor for indicators of compromise as described above.
  6. Conduct a forensic review of any LoadMaster appliance that may have been exposed prior to patching.

Given that this is a CISA-tracked vulnerability with active exploitation, every day of delay increases the risk of compromise.

Frequently Asked Questions

Q: Does this vulnerability require authentication? A: No. CVE-2026-8037 is a pre-authentication vulnerability. Any attacker who can reach the LoadMaster API can attempt exploitation without credentials.

Q: Is the API enabled by default? A: The API is a configurable feature. Many enterprise deployments enable it for management automation. Check your LoadMaster configuration to determine if the API is exposed.

Q: Does this affect cloud-hosted LoadMaster instances? A: Yes, any instance running an affected version with the API enabled is vulnerable, regardless of deployment model.

Q: Is there a bypass for the WAF recommendations? A: Progress also addressed a separate WAF bypass vulnerability (CVE-2026-21876) in the same advisory. Organizations should ensure both CVEs are addressed.

Q: How does this relate to the MOVEit vulnerability from 2023? A: Both affect Progress Software products, but they are entirely separate vulnerabilities. Progress is the parent company that acquired Kemp. The LoadMaster vulnerability is in a different product line.

Q: Can I detect if my system has been compromised? A: Review API access logs for unusual requests containing shell metacharacters, check for unexpected processes, monitor network connections from the appliance, and verify file integrity on system binaries.

Key Takeaways

  • CVE-2026-8037 is a critical pre-auth RCE in Progress Kemp LoadMaster with a CVSS score of 9.6
  • The root cause is an uninitialized heap bug in the command escaping function
  • Active exploitation is underway, with CISA tracking the vulnerability
  • Patches are available for all affected product lines
  • No authentication is required for exploitation
  • Organizations should treat this with the same urgency as the MOVEit incident
  • Patch immediately and review for signs of compromise

Conclusion

The Kemp LoadMaster CVE-2026-8037 vulnerability represents a serious threat to any organization using Progress load balancing products. The combination of pre-authentication access, root-level code execution, and active exploitation makes this a must-patch event. Security teams should prioritize patching LoadMaster appliances today, before attackers turn proof-of-concept code into widespread campaigns. The detailed technical analysis from watchTowr Labs demonstrates that the exploit path is well understood, making it only a matter of time before automated scanning and exploitation becomes routine.


Sources: The Hacker News, watchTowr Labs, NVD - CVE-2026-8037, SC Media, Progress Community Advisory

Automated Transmission

This entry was synthesized and populated dynamically using native API integrations.

Resources & Links