The critical vulnerability in Progress Kemp LoadMaster highlights the risks created when management APIs are exposed on internet-facing network appliances.
Tracked as CVE-2026-8037, the flaw can allow an unauthenticated attacker to send a specially crafted API request and execute arbitrary commands with root privileges. No valid credentials are required when the vulnerable API is enabled.
LoadMaster is commonly deployed as a load balancer and application delivery controller at the network edge. A successful compromise could allow attackers to modify configurations, intercept or redirect traffic, steal credentials, access internal applications, and use the appliance as an entry point into the wider network.
Affected versions include LoadMaster GA 7.2.63.1 and earlier, and LTSF 7.2.54.17 and earlier. Organizations should upgrade to GA 7.2.63.2, LTSF 7.2.54.18, or a later supported release.
There were no confirmed attacks at the time of disclosure, but detailed technical analysis and a working proof of concept are now publicly available. This significantly increases the likelihood of scanning and exploitation attempts.
Administrators should also review whether the API needs to be enabled or reachable from untrusted networks. Management and API access should be restricted to approved administrative systems, VPN users, or dedicated management networks.
The key lesson is that perimeter appliances should never be treated as ordinary infrastructure. A pre-authentication flaw that provides root access can turn the system responsible for directing enterprise traffic into an attacker-controlled gateway.

A critical vulnerability in Progress Kemp LoadMaster can let an unauthenticated attacker execute arbitrary commands as root on the appliance by sending a crafted request to its API. The flaw, tracked as CVE-2026-8037, carries a CVSS score of 9.8 according to ZDI. A patch is available. If you run LoadMaster with the API enabled, update now. Progress published its advisory on June
Source: Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth via The Hacker News — published 30 Jun 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.