vulnerability
Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth
Critical
Summary
A critical vulnerability (CVE-2026-8037) in Progress Kemp LoadMaster allows unauthenticated attackers to execute arbitrary commands as root by manipulating API requests. The flaw stems from a lack of proper sanitization of user input, specifically a missing null terminator in a memory buffer. Progress has released patches, and the vulnerability has been independently analyzed and demonstrated by watchTowr Labs and TrendAI Research.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
