All stories
criticalExploited VulnerabilitiesCVE-2026-8037

Unauthenticated attackers can execute remote commands on Progress Kemp LoadMaster appliances via API flaw

馃毃 Critical command injection vulnerability found in Progress LoadMaster appliances. An unauthenticated attacker can execute arbitrary commands on the device via its API. Patch your LoadMaster instances immediately to prevent full system compromise.

Summary

A critical vulnerability in the API of Progress ADC products, specifically affecting the LoadMaster appliance, allows for remote code execution. The flaw stems from unsanitized input within multiple command endpoints. Because the vulnerability can be triggered without authentication, an attacker with network access to the appliance's API can execute arbitrary commands on the underlying operating system.

Technical details

The vulnerability, identified as CVE-2026-8037, carries a CVSS score of 9.6. The flaw resides in how the LoadMaster API processes input for various command endpoints. An attacker can supply malicious, unsanitized strings that the system then executes as OS commands.

This injection vulnerability provides high levels of impact across confidentiality, integrity, and availability. Successful exploitation allows an unauthenticated actor to gain control over the appliance, potentially leading to full network pivoting or service disruption.

Affected products and fixed versions

The vulnerability affects Progress LoadMaster appliances. While specific version numbers are not detailed in the provided advisory text, all current versions of the LoadMaster ADC product using the vulnerable API endpoints are at risk.

Users should consult the official Progress security bulletin for specific version-to-patch mapping and to confirm if their specific deployment is covered by the fix.

Why this matters for defenders

Load balancers and Application Delivery Controllers (ADCs) like LoadMaster often sit at the edge of a network or in front of critical application infrastructure. A compromise here provides an attacker with high-level visibility into traffic patterns and a foothold within the internal network.

Since the attack vector requires no authentication, any actor capable of reaching the API endpoints can attempt to execute commands. This makes the vulnerability highly exploitable once a target is identified.

Defender guidance

Apply the security updates provided by Progress Software immediately. Prioritize all LoadMaster appliances that are reachable via the network or have exposed API services.

If immediate patching is not possible, restrict access to the LoadMaster API endpoints using firewall rules or ACLs to ensure only trusted administrative hosts can communicate with the management interface. Monitor system logs for unusual command execution patterns or unexpected API calls.

Sources

  1. https://thehackernews.com/2026/07/latest-progress-kemp-loadmaster-pre.html
  2. https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691
Harith Dilshan

Harith Dilshan

- Offensive Security Engineer | Ethical Hacker | Penetration Tester -