ZeroHour
ZDI Published Advisoriespublished ()ingested

ZDI-26-646: Progress Software Kemp LoadMaster escape_quotes Uninitialized Memory Remote Code Execution Vulnerability

mediumAdvisoryimportance 28CVE-2026-8037
AI summary · glm-5.3-flash

ZDI publishes ZDI-26-646 for CVE-2026-8037, an authenticated uninitialized-memory remote code execution flaw in Progress Kemp LoadMaster, rated CVSS 7.2.

Zero Day Initiative published advisory ZDI-26-646 describing an uninitialized memory flaw in Progress Software Kemp LoadMaster's escape_quotes function. Successful exploitation allows remote authenticated attackers to execute arbitrary code on affected installations. ZDI rated the issue CVSS 7.2 and assigned CVE-2026-8037.

  • Uninitialized memory in escape_quotes allows arbitrary code execution
  • Authentication is required to exploit the flaw
  • CVSS 7.2; tracked as CVE-2026-8037

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-8037
Unauthenticated OS Command Injection RCE in Progress Kemp LoadMaster

Progress Kemp LoadMaster, the application delivery controller/load balancer sold by Progress Software (formerly Kemp), contains an unauthenticated OS command injection flaw (CWE-77) in its API: unsanitized input sent to multiple command endpoints allows arbitrary operating-system commands to be executed on the appliance. Because the affected endpoints require no authentication, any remote attacker with network access to the appliance's API or management interface can trigger the bug directly; public research by WatchTowr describes it as a pre-authentication RCE chain (involving uninitialized memory/quote handling) that can yield root-level command execution. Successful exploitation gives an attacker full control of the appliance, consistent with the Critical 9.8 CVSS 3.1 score (network-exploitable, no privileges or user interaction, high impact on confidentiality, integrity and availability). Organizations running Progress Kemp LoadMaster appliances are affected, especially those where the management or API interface is reachable from the internet. Exploitation is confirmed and ongoing: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-08-07 after 792 reported exploit attempts, and EPSS assigns a 99.6% probability of exploitation within 30 days.

Do: Upgrade LoadMaster to the fixed release identified in Progress's security advisory (fixed version numbers are not specified in this data). Until patched, restrict the LoadMaster API/management interface to trusted networks or VPN access, and review appliance logs for signs of unexpected command execution given confirmed in-the-wild exploitation. Because the flaw is on CISA's KEV catalog, US federal agencies must apply mitigations per BOD 26-04 by the required deadline — or discontinue use of the product if mitigations are unavailable — and evaluate each asset's internet exposure.

9.8100% KEV PoC
  • Progress LoadMaster (Kemp LoadMaster ADC/load balancer)
  • Progress Connection Manager for ObjectScale
  • Progress ECS Connection Manager
  • +1 more
largetens of thousands of internet-exposed LoadMaster appliances (order of magnitude: 10,000–100,000 devices)
Full article

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Progress Software Kemp LoadMaster. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-8037.

This source does not provide full text. Read it at zerodayinitiative.com.