Summary
A critical pre-authentication remote code execution vulnerability in Progress Kemp LoadMaster appliances (CVE-2026-8037, CVSS 9.8) is being actively exploited following the public release of proof-of-concept exploit code. The flaw allows unauthenticated attackers to execute arbitrary commands with root privileges on affected devices.
The vulnerability stems from improper handling of user input in the escape_quotes() function, which fails to properly null-terminate escaped strings, leading to out-of-bounds reads into adjacent heap memory. Attackers can exploit this by sending crafted JSON requests to the /accessv2 API endpoint, manipulating heap memory to inject and execute commands.
Progress disclosed and patched the vulnerability on June 4, 2026, but active exploitation attempts began around June 29 after a functional PoC was published. Affected versions include LoadMaster GA v7.2.63.1 and older, and LTSF v7.2.54.17 and older.
Sources
Commentary
Load balancers are the front door to an organization’s infrastructure, and a pre-auth RCE with root access is about as bad as it gets. The 25-day gap between Progress releasing the patch and active exploitation beginning is a textbook example of the shrinking window defenders have after a vulnerability is disclosed — especially once a PoC drops.
If you’re running Kemp LoadMaster, check your version immediately. These devices are often internet-facing by design, which makes them trivially discoverable via services like Shodan. The combination of unauthenticated access, root-level execution, and public PoC code makes this a recipe for mass exploitation.
