Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-1212 | Unauthenticated OS Command Injection RCE in Progress Kemp LoadMaster CVE-2024-1212 is a critical (CVSS 9.8) unauthenticated OS command injection flaw (CWE-78) in the management interface of Progress Kemp LoadMaster, a load balancer / application delivery appliance. A remote attacker with no credentials can send crafted requests to the management interface, causing the appliance to execute arbitrary operating system commands; security reporting indicates commands can be run with root privileges. Successful exploitation gives attackers full control of the appliance and potential access to the backend servers and traffic it manages. Any organization running an affected Kemp LoadMaster appliance or virtual appliance whose management interface is reachable is exposed. Exploitation is occurring in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-11-18, carries a 95.4% EPSS probability of exploitation within 30 days, and recent headlines report active exploitation attempts. Do: Apply the vendor-supplied update immediately per Progress's advisory (the CISA KEV required action is to apply vendor mitigations or discontinue use of the product), since no public PoC is needed for attackers to exploit it. Until patched, restrict the LoadMaster management interface (web UI and API) to trusted management networks behind a firewall or VPN, and review appliance logs for signs of unauthenticated access or unexpected command execution. Treat any suspected compromise as high risk, as ransomware use is currently unknown. | 9.8 | 95% | KEV |
| largetens of thousands of internet-exposed LoadMaster appliances | |
| CVE-2026-8037 | Unauthenticated OS Command Injection RCE in Progress Kemp LoadMaster Progress Kemp LoadMaster, the application delivery controller/load balancer sold by Progress Software (formerly Kemp), contains an unauthenticated OS command injection flaw (CWE-77) in its API: unsanitized input sent to multiple command endpoints allows arbitrary operating-system commands to be executed on the appliance. Because the affected endpoints require no authentication, any remote attacker with network access to the appliance's API or management interface can trigger the bug directly; public research by WatchTowr describes it as a pre-authentication RCE chain (involving uninitialized memory/quote handling) that can yield root-level command execution. Successful exploitation gives an attacker full control of the appliance, consistent with the Critical 9.8 CVSS 3.1 score (network-exploitable, no privileges or user interaction, high impact on confidentiality, integrity and availability). Organizations running Progress Kemp LoadMaster appliances are affected, especially those where the management or API interface is reachable from the internet. Exploitation is confirmed and ongoing: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-08-07 after 792 reported exploit attempts, and EPSS assigns a 99.6% probability of exploitation within 30 days. Do: Upgrade LoadMaster to the fixed release identified in Progress's security advisory (fixed version numbers are not specified in this data). Until patched, restrict the LoadMaster API/management interface to trusted networks or VPN access, and review appliance logs for signs of unexpected command execution given confirmed in-the-wild exploitation. Because the flaw is on CISA's KEV catalog, US federal agencies must apply mitigations per BOD 26-04 by the required deadline — or discontinue use of the product if mitigations are unavailable — and evaluate each asset's internet exposure. | 9.8 | 100% | KEV PoC |
| largetens of thousands of internet-exposed LoadMaster appliances (order of magnitude: 10,000–100,000 devices) |
Full article335 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananJul 01, 2026Vulnerability / Network Security
A recently disclosed critical security flaw impacting Progress Kemp LoadMaster is seeing active exploitation attempts, according to an advisory from eSentire's Threat Response Unit (TRU).
The Canadian cybersecurity company said it identified exploitation attempts targeting CVE-2026-8037 (CVSS score: 9.6), an operating system (OS) command injection flaw that could be exploited to achieve arbitrary code execution on susceptible devices. The exploitation activity commenced on June 29, 2026.
"OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an unauthenticated attacker with permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input," Progress said in an advisory for the vulnerability released early last month.
In an analysis published this week, watchTowr Labs described the flaw as rooted in a function named "escape_quotes()" within the load balancer application and that it stems from improper handling of user-supplied input.
The problem was that the function failed to properly null-terminate sanitized strings, thereby leading to an out-of-bounds read into adjacent heap memory. An attacker could weaponize this loophole to issue specially crafted requests to the "/accessv2" endpoint that manipulate the heap memory to enable command injection.
The impact of successful exploitation is severe, as it allows an unauthenticated attacker to run arbitrary commands on the affected appliance without having to possess valid credentials.
eSentire noted that exploitation efforts it observed ended in failure, as a result of which no post-compromise activity occurred. However, the availability of a proof-of-concept (PoC) exploit and detailed technical specifics is expected to drive malicious activity against CVE-2026-8037 in the immediate future.
The attack attempts originate from the following IP addresses -
- 192.42.116[.]58
- 192.42.116[.]105
- 146.70.139[.]154
CVE-2026-8037 is the second Progress Progress Kemp LoadMaster flaw to witness active exploitation efforts after CVE-2024-1212 (CVSS score: 10.0), another critical OS command injection vulnerability that could be abused for arbitrary system command execution.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/07/latest-progress-kemp-loadmaster-pre.html