Threat Advisory

Progress Kemp LoadMaster Flaw Enables Arbitrary Code Execution

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A critical-severity command injection flaw, tracked as CVE-2026-8037 with a CVSS score of 9.6, has been added to the Known Exploited Vulnerabilities catalog by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) following reports of active exploitation in the wild. The vulnerability allows an unauthenticated attacker to execute arbitrary commands on susceptible devices by exploiting unsanitized input in multiple command endpoints, ultimately enabling arbitrary code execution without valid credentials. Successful exploitation can lead to significant business impact as attackers may gain unauthorized access to sensitive data or disrupt critical operations. A total of 792 exploitation attempts have been observed over the last 41 days from 65 unique IP addresses across 18 countries, highlighting the urgency for affected organizations to apply necessary patches and secure their networks in accordance with Binding Operational Directive (BOD) 26-04.

RECOMMENDATION:

We recommend you to update refer below mention link to apply patches: https://docs.progress.com/category/kemp-documentation[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A critical-severity command injection flaw, tracked as CVE-2026-8037 with a CVSS score of 9.6, has been added to the Known Exploited Vulnerabilities catalog by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) following reports of active exploitation in the wild. The vulnerability allows an unauthenticated attacker to execute arbitrary commands on susceptible devices by exploiting unsanitized input in multiple command endpoints, ultimately enabling arbitrary code execution without valid credentials. Successful exploitation can lead to significant business impact as attackers may gain unauthorized access to sensitive data or disrupt critical operations. A total of 792 exploitation attempts have been observed over the last 41 days from 65 unique IP addresses across 18 countries, highlighting the urgency for affected organizations to apply necessary patches and secure their networks in accordance with Binding Operational Directive (BOD) 26-04.

RECOMMENDATION:

We recommend you to update refer below mention link to apply patches: https://docs.progress.com/category/kemp-documentation[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu