Security · 4h ago
Critical LoadMaster Bug Lets Attackers Execute Root Commands Remotely
A pre-auth vulnerability in Progress Kemp LoadMaster, CVE-2026-8037 with a CVSS score of 9.8, allows unauthenticated attackers to execute arbitrary root commands via crafted API requests. The flaw impacts appliances with the API enabled. Progress has released a patch, urging immediate updates.
Meridian48 take
This is a severe, remotely exploitable flaw in a widely used load balancer, but the real story is how many organizations will fail to patch before attackers weaponize it.
Read the full reporting
Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth →
The Hacker News
loadmaster-vulnerabilitycve-2026-8037