A critical vulnerability in Progress Kemp LoadMaster could allow an unauthenticated attacker to execute arbitrary commands with root privileges on the device by sending a specially crafted request to its API . Progress Kemp LoadMaster is widely used by enterprises as an application delivery controller and load balancer for managing network traffic, making the vulnerability particularly dangerous. A security update is available and immediate implementation is highly recommended.
See also: CISA: Progress Kemp LoadMaster flaw exploited in attacks

CVE-2026-8037: What is Progress Kemp LoadMaster and why is the vulnerability so serious?
The vulnerability is tracked as CVE-2026-8037 and carries a CVSS score of 9.8 according to the Zero Day Initiative (ZDI) — one of the highest possible scores on the risk scale. LoadMaster sits at the network edge, acting as an entry point for application traffic. This means that any pre-authentication vulnerability in it can be exploited without the attacker needing valid credentials, making the attack extremely easy to execute. Progress Software published its announcement on June 4, 2026 , and stated that it has not received any reports of exploitation in practice.
On June 29, 2026, researchers at watchTowr Labs published a detailed technical analysis describing the entire exploitation chain, including a working proof of concept (PoC). This publication significantly increases the risk, as anyone with basic technical knowledge can now attempt to exploit it. The vulnerability was discovered by Syed Ibrahim Ahmed of TrendAI Research and reported to Progress via the Zero Day Initiative on April 15, 2026.
Technical analysis of the Progress Kemp LoadMaster vulnerability
The root of the problem lies in a function called escape_quotes(), which is responsible for sanitizing user input before it is passed to a shell. The purpose of the function is to "escape" single quotes so that an attacker cannot break the string and enter commands. The problem is that the function allocated a memory buffer without first zeroing it and never wrote a null terminator at the end of the sanitized string.
This missing null terminator is the key to the entire exploit. Without it, the system continues reading past the end of the sanitized input, into whatever data happens to be adjacent in memory. An attacker can check what's there by "stuffing" additional JSON keys into the same API request, each of which carries a command injection payload. The system reads the sanitized input, continues, "hits" the attacker's payload, and executes it.
The attack targets the /accessv2, which handles API credential validation. The attacker sends a JSON body with a specially crafted apiuser and dozens of additional key-value pairs carrying the command they want to execute. No valid credentials are required. The command is executed as root.
The fix is minimal but effective. Two changes were made: the memory allocation function was replaced with one that zeroes the buffer, and an explicit null terminator was added after the sanitized output. Two lines of code that close a path to root privileges . Progress also fixed a second, high-severity vulnerability in the same announcement: CVE-2026-33691 , a WAF bypass where padding with spaces in filenames could bypass file extension checks during upload.
See also: Command Injection vulnerability in Kemp Load Balancer

Progress Kemp LoadMaster vulnerability history and immediate update recommendation
This is not the first critical LoadMaster vulnerability . In November 2024 , CISA added a previous LoadMaster command injection vulnerability ( CVE - 2024-1212 , CVSS 10.0 ) to the Known Exploited Vulnerabilities list after a confirmed exploit in action. In April 2026 , Progress patched five other high-severity vulnerabilities in LoadMaster , four of which were command injection issues . It is worth noting that Progress is also the maker of MOVEit , whose 2023 vulnerabilities fueled a massive exploitation campaign by the Cl0p ransomware group .
The Canadian Centre for Cyber Security has also issued a statement urging administrators to implement the updates immediately. Given that a working proof of concept is now publicly available, the risk of exploitation is high. Organizations using LoadMaster with the API should update immediately and assess whether the API needs to be accessible from the network. Restricting access to the API to only trusted IP addresses and monitoring for suspicious requests to the /accessv2 are additional mitigation measures.
See also: Progress Telerik Report Servers: PoC exploit for vulnerabilities released – Update immediately!

Overall, CVE-2026-8037 is a reminder that even small errors in memory management — like a missing null terminator — can lead to a complete system compromise. No attacks have been reported yet, but with a public PoC available, the window for action is narrow. Applying the update immediately is the only effective defense.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
