What it is
CVE-2026-8037 is an unauthenticated vulnerability affecting Progress Software LoadMaster and 3 other products. OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an...
Vulnerability report
LoadMaster Command Injection
Progress Software / LoadMaster · affected before V7.2.63.2
Decision summary
Direct answers before the deeper technical record.
What it is
CVE-2026-8037 is an unauthenticated vulnerability affecting Progress Software LoadMaster and 3 other products. OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an...
Is it exploited?
Yes. KEV Intelligence sensors observed exploitation attempts with confirmed confidence.
Who is affected?
Progress Software / LoadMaster affected before v7.2.63.2.
What should we do?
Patch immediately, validate internet-facing exposure, and monitor for matching requests.
Overview
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints
Exploitation evidence
Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.
TheHackerNews
Independent exploitation attestation added to the KEV Intelligence record.
KEV Intelligence sensor
First-party sensor telemetry confirms matching exploitation attempts.
GitHub
Public scanner or PoC coverage increases practical exploitability.
Per-source evidence links for KEV attestations are available through the KEV Intelligence Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| TheHackerNews First | 2026-07-01 14:51 UTC |
| KEV Intelligence | 2026-07-01 17:30 UTC |
| The Shadowserver | 2026-07-09 00:00 UTC |
| CISA | 2026-08-07 16:45 UTC |
| CVE | 2026-08-07 18:10 UTC |
Operational indicators for this CVE are listed under Detection.
Sensor telemetry
Aggregate observations show the scale, recency, and distribution of activity without overstating sparse data.
743
Attempts observed
61
Unique attacker IPs
19
Attacker countries
AU · CA · CN · DE · ES · HK · ID · IN · IQ · JP · KR · NL · PK · PL · RO · SG · TR · TW · US
6
Sensors observed
Exploitation attempts over the last 49 days
Daily events observed by KEV Intelligence sensors
Updated 16 Aug 2026
First observed 30 Jun 2026 · Last observed 14 Aug 2026
Pro adds sensor region and window summaries. Enterprise adds raw IPs, paths, User-Agents, and payloads.
Detection
Make the evidence actionable in scanner, SOC, and edge-control workflows.
Raw values available in Pro and Enterprise.
Nuclei template detected 02 Jul 2026.
View Nuclei template (opens in new tab)KEV Intelligence virtual patch guidance is available for this CVE.
Operational indicators linked to exploitation of this CVE. IoCs age over time — especially IP addresses.
| Type | Indicator | First Seen | Last Seen | Age | Source |
|---|---|---|---|---|---|
| IP |
192.42.116.58
|
2026-06-30 14:53 UTC | 2026-06-30 14:53 UTC | about 2 months ago | Source |
| IP |
192.42.116.105
|
2026-06-30 14:53 UTC | 2026-06-30 14:53 UTC | about 2 months ago | Source |
| IP |
146.70.139.154
|
2026-06-30 14:53 UTC | 2026-06-30 14:53 UTC | about 2 months ago | Source |
Scanner and exploit-framework references linked to this CVE.
| Scanner | Reference | Detected |
|---|---|---|
| Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-8037.yaml | 02 Jul 2026 |
Compensating WAF rules for this CVE.
Enterprise feature. Virtual patch rule content and deployable vendor exports (ModSecurity, Cloudflare, AWS WAF) are available to KEV Intelligence Enterprise users.
Risk and context
CVSS v3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS
99.3%
Recent mention · TheHackerNews
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. The vulnerability,...
Read full advisoryRecent mention · TheHackerNews
Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit AttemptsTheHackerNews · 08 Aug 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. The vulnerability, tracked as CVE-2026-8037 (CVSS score: 9.6), is a command injection flaw that could be weaponized to achieve arbitrary
Recent mention · TheHackerNews
Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation AttemptsTheHackerNews · 01 Jul 2026
A recently disclosed critical security flaw impacting Progress Kemp LoadMaster is seeing active exploitation attempts, according to an advisory from eSentire's Threat Response Unit (TRU). The Canadian cybersecurity company said it identified exploitation attempts targeting CVE-2026-8037 (CVSS score: 9.6), an operating system (OS) command injection flaw that could be exploited to achieve
Recent mention · TheHackerNews
Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-AuthTheHackerNews · 30 Jun 2026
A critical vulnerability in Progress Kemp LoadMaster can let an unauthenticated attacker execute arbitrary commands as root on the appliance by sending a crafted request to its API. The flaw, tracked as CVE-2026-8037, carries a CVSS score of 9.8 according to ZDI. A patch is available. If you run LoadMaster with the API enabled, update now. Progress published its advisory on June
Recent mention · Watchtower Labs
Enterprise Tech In, Shell Out (Progress Kemp LoadMaster Uninitialized Heap to Pre-Auth RCE CVE-2026-8037)Watchtower Labs · 29 Jun 2026
Welcome back to another watchTowr Labs blog post.This time, we're looking at Progress Kemp LoadMaster, a load balancer that sits at the edge of a lot of enterprise networks. Edge appliances have a habit of becoming the way in rather than the thing keeping people out, and
Recent mention · Zero Day Initiative Published Advisories
ZDI-26-340: Progress Software Kemp LoadMaster dodelapikey Uninitialized Memory Remote Code Execution VulnerabilityZero Day Initiative Published Advisories · 09 Jun 2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Progress Software Kemp LoadMaster. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-8037.
Recent mention · Zero Day Initiative Published Advisories
ZDI-26-341: Progress Software Kemp LoadMaster dolistapikeys Uninitialized Memory Remote Code Execution VulnerabilityZero Day Initiative Published Advisories · 09 Jun 2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Progress Software Kemp LoadMaster. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-8037.
Recent mention · Zero Day Initiative Published Advisories
ZDI-26-342: Progress Software Kemp LoadMaster apiuser Uninitialized Memory Remote Code Execution VulnerabilityZero Day Initiative Published Advisories · 09 Jun 2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Progress Software Kemp LoadMaster. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2026-8037.
These PoCs are unverified and could contain malware. Use at your own risk.
nuclei · Created Unknown
Timeline
Exploitation attested by an external source
Listed in the CISA Known Exploited Vulnerabilities catalog
Exploitation attested by an external source
Compensating WAF rule available to block exploitation
Public proof-of-concept code published
Scanner coverage available
Evidence-backed exploitation signal
High-confidence, third-party attested exploitation
Indicators of compromise recorded
Vulnerability disclosed publicly
Identifier reserved by the CNA
Pro API
Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
GET /api/v2/pro/kevs/CVE-2026-8037
Free JSON includes basic KEV fields{
"cve_id": "CVE-2026-8037",
"confidence": "Confirmed",
"cvss_score": 9.6,
"epss_score": 0.99311,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": true
},
"sensor_telemetry": { "attempts": 743, "sensors": 6 }
}
Early warning alerts
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.