Progress Kemp LoadMaster pre-auth command injection under active exploit
Source headline: Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts
Intelligence Summary
A critical Progress Kemp LoadMaster vulnerability is being actively targeted in the wild. Security firm eSentire’s Threat Response Unit reports exploitation attempts linked to CVE-2026-8037. The flaw is an OS command injection reachable pre-auth, which can enable attackers to run commands. With a CVSS score of 9.6, the risk includes potential compromise without valid credentials. LoadMaster administrators should check for available patches and validate that mitigations and configuration hardening are applied.
Recommended Action
Check whether your Kemp LoadMaster deployment is affected by CVE-2026-8037 (CVSS 9.6) and apply the vendor fix. Until then, watch authentication and outbound traffic logs for the indicators described in the source. This signal rests on a single report, so corroborate it before acting on anything irreversible.