CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →
← Back to Daily brief 2026-06-30
HIGHCVE-2026-8037exploitedupdatedvulnerability

CVE-2026-8037, Progress Kemp LoadMaster: pre-auth RCE via uninitialized heap in the /accessv2 API

Defender actions

  • Patch Kemp LoadMaster or disable its API, exploitation attempts against CVE-2026-8037 began the day the PoC dropped; apply the early-June firmware and, where the /accessv2 API is not required, disable it to remove the attack surface entirely.
  • Re-verify every Kemp LoadMaster is on GA 7.2.63.2 or the corresponding LTSF fixed build from Progress's June bulletin and, for any appliance that was internet-reachable with the API enabled before it was patched, run a compromise assessment of the appliance rather than closing the ticket on the version string.

Analysis

CVE-2026-8037 (CVSS 9.8) is a pre-authentication RCE in Progress Kemp LoadMaster, an edge load balancer (watchTowr Labs, 2026-06-29 · Trend Micro ZDI, 2026-06-09). The escape_quotes() function in the access executable allocates buffers via uninitialized malloc() without null-terminating escaped strings; a sprayed JSON payload to /accessv2 (four single-quotes expanding to 16 bytes) overwrites heap metadata in adjacent freed chunks, and the subsequent __sprintf_chk() reads out-of-bounds into attacker-controlled data, reaching code execution as root with no authentication. watchTowr published the full mechanics. Affected: GA ≤ 7.2.63.1 and LTSF ≤ 7.2.54.17; fixed in v7.2.63.2 (which switches to calloc() with proper null termination). A second bulletin CVE, CVE-2026-33691, bypasses file-upload extension checks via OWASP CRS whitespace padding. Progress reports no known active exploitation. Hardening: patch to v7.2.63.2 and restrict the management interface to a dedicated admin VLAN; perimeter anomaly detection for unusual character sequences in JSON POSTs to /accessv2.

Cited evidence

UPDATE (originally covered 2026-06-30): eSentire's Threat Response Unit reports that in-the-wild exploitation attempts against CVE-2026-8037, the Progress Kemp LoadMaster pre-auth OS command-injection flaw reachable through the /accessv2 API endpoint (CVSS 9.6–9.8), began 2026-06-29, the same day …

ctipilot v2 brief (migrated)

based on evidence of active exploitation.

CISA 2026-08-07

Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.

CISA (KEV catalog record)

Kemp LoadMaster: GA v7.2.63.1 and older

watchTowr Labs

Updates2

Update

ESentire's Threat Response Unit reports that in-the-wild exploitation attempts against CVE-2026-8037, the Progress Kemp LoadMaster pre-auth OS command-injection flaw reachable through the /accessv2 API endpoint (CVSS 9.6–9.8), began 2026-06-29, the same day a public proof-of-concept was released, confirming the compressed PoC-to-exploitation timeline (eSentire TRU, 2026-06-30).

The observed attempts were unsuccessful, with no post-compromise activity, but eSentire assesses that public PoC availability plus detailed technical write-ups will drive continued and likely more successful attacks near-term (The Hacker News, 2026-07-01). Affected versions remain LoadMaster 7.2.63.1 and earlier (GA) and 7.2.54.17 and earlier (LTSF); Progress shipped patched firmware in early June 2026. Patch remains the primary mitigation; disabling the LoadMaster API where not required removes the /accessv2 attack surface entirely. Hunt /accessv2 traffic for malformed/oversized parameters and repeated probing from related sources in a short window (T1190 → T1059).

Update

CISA added CVE-2026-8037 to its Known Exploited Vulnerabilities catalog on 2026-08-07, "based on evidence of active exploitation" (CISA, 2026-08-07). The catalog record describes the flaw as a command injection that "allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints," classes it CWE-77, and records known ransomware-campaign use as unknown (CISA, 2026-08-07).

The delta is the status, not the mechanics. This pipeline's 2026-07-02 entry recorded exploitation attempts beginning the day the proof-of-concept dropped, all of them unsuccessful with no post-compromise activity; a federal catalog entry asserting active exploitation is a different claim, arriving five weeks later. Nothing in the affected estate has changed: watchTowr Labs gives the vulnerable version range as "Kemp LoadMaster: GA v7.2.63.1 and older" together with the LTSF release v7.2.54.17 and older, in both cases only when the API is enabled (watchTowr Labs, 2026-06-29). No authority has named an exploiting cluster or described an observed intrusion path.

The catalog's remediation due date is a US federal compliance clock and carries no weight here. What does carry weight is the interval: a public exploit has existed since late June against an appliance class that terminates traffic at the network edge, and the flaw needs nothing but reachability to the API. An organisation that patched in June is fine. An organisation that has been treating this as a scheduled item now has a gap between the PoC and its own patch date during which a working, public exploit was being fired at exposed instances.

Detection remains network-side rather than host-side, because the appliance does not normally surface process telemetry to defenders: in reverse-proxy or web-application-firewall logs in front of the management API, unauthenticated POST requests to the /accessv2 endpoint carrying malformed or oversized parameters, and repeated probing of that endpoint from related sources in a short window, are the observable shape (watchTowr Labs, 2026-06-29). Triage: legitimate LoadMaster API clients authenticate and send well-formed payloads from a small, stable set of management sources; the discriminators are an unauthenticated request reaching /accessv2 at all, and parameter content that is malformed rather than merely unexpected. Hardening is unchanged and still the strongest control available: disable the LoadMaster API where it is not required, which removes the endpoint entirely, and keep the management interface off any general-purpose network.

Sources5

Revision history

  1. Published 2026-06-30-9aaa1114
  2. Update 2026-07-02-6551f8c2

    Kemp LoadMaster exploitation now confirmed. eSentire reports in-the-wild exploitation attempts against the pre-auth command-injection CVE-2026-8037 began 29 June (the same day a public PoC dropped) though observed attempts failed (eSentire TRU).

    Changed: actions cves evidence sources tags body

  3. Update 2026-08-08T0409Z-intel

    CISA added CVE-2026-8037 to its Known Exploited Vulnerabilities catalog on 2026-08-07, based on evidence of active exploitation of the unauthenticated command-injection flaw in Progress Kemp LoadMaster. When this pipeline last covered it on 2026-07-02 the only observed activity was exploitation attempts that eSentire reported as unsuccessful. Every LoadMaster running a version at or below GA 7.2.63.1, or the LTSF release 7.2.54.17, with the API enabled is affected; any appliance that sat internet-reachable and unpatched between the 29 June proof-of-concept and now warrants a compromise assessment rather than an upgrade alone.

    Changed: actions affected_products cves evidence sources tags techniques body

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.