---
schema: 1
kind: vulnerability
title: >
  CVE-2026-8037 — Progress Kemp LoadMaster: pre-auth RCE via uninitialized heap in the /accessv2
  API
headline: >
  CVE-2026-8037 — Progress Kemp LoadMaster: pre-auth RCE via uninitialized heap in the /accessv2
  API
summary: >
  Progress Kemp LoadMaster pre-auth RCE (CVE-2026-8037, CVSS 9.8) — uninitialized-malloc heap
  corruption in the /accessv2 API reaches code execution as root. watchTowr published the full
  mechanics; Progress reports no known exploitation; patch is in v7.2.63.2.
discovered_at: "2026-06-30T05:10:38Z"
updated_at: "2026-08-08T04:45:00Z"
event_date: 2026-06-29
run_id: 2026-06-30-9aaa1114
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - rce
  - pre-auth
  - patch-available
  - actively-exploited
  - poc-public
  - cisa-kev
regions:
  - global
sectors:
  - technology
  - telco
  - public-sector
entities: []
techniques:
  - T1190
  - T1059
affected_products:
  - Progress Kemp LoadMaster
cves:
  - id: CVE-2026-8037
    cvss: "9.8"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - exploited
      - cisa-kev
      - poc-public
      - patch-available
    affected: "Kemp LoadMaster GA 7.2.63.1 and older; LTSF 7.2.54.17 and older, when the API is enabled"
    fixed: >
      GA release 7.2.63.2 (the fixed build watchTowr diffed against the vulnerable one); the
      corresponding LTSF fixed build is named in neither source cited here
sources:
  - url: "https://labs.watchtowr.com/enterprise-tech-in-shell-out-progress-kemp-loadmaster-uninitialized-heap-to-pre-auth-rce-cve-2026-8037/"
    publisher: watchTowr Labs
    role: primary
  - url: "https://www.zerodayinitiative.com/advisories/ZDI-26-342/"
    publisher: Trend Micro Zero Day Initiative
    role: corroborating
  - url: "https://www.esentire.com/security-advisories/progress-kemp-loadmaster-vulnerability-targeted-cve-2026-8037"
    publisher: eSentire TRU
    role: primary
  - url: "https://thehackernews.com/2026/07/latest-progress-kemp-loadmaster-pre.html"
    publisher: The Hacker News
    role: corroborating
  - url: "https://www.cisa.gov/news-events/alerts/2026/08/07/cisa-adds-one-known-exploited-vulnerability-catalog"
    publisher: CISA
    date: 2026-08-07
    role: primary
closed_sources: []
evidence:
  - quote: "UPDATE (originally covered 2026-06-30): eSentire's Threat Response Unit reports that in-the-wild exploitation attempts against CVE-2026-8037 — the Progress Kemp LoadMaster pre-auth OS command-injection flaw reachable through the /accessv2 API endpoint (CVSS 9.6–9.8) — began 2026-06-29, the same day …"
    publisher: ctipilot v2 brief (migrated)
  - quote: based on evidence of active exploitation.
    publisher: CISA
  - quote: Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.
    publisher: CISA (KEV catalog record)
  - quote: "Kemp LoadMaster: GA v7.2.63.1 and older"
    publisher: watchTowr Labs
verification: multi-source
sourcing_note: null
confidence: high
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification: null
watchlist_hit: false
actions:
  - "**Patch Kemp LoadMaster or disable its API** — exploitation attempts against CVE-2026-8037 began the day the PoC dropped; apply the early-June firmware and, where the `/accessv2` API is not required, disable it to remove the attack surface entirely."
  - "Re-verify every Kemp LoadMaster is on GA 7.2.63.2 or the corresponding LTSF fixed build from Progress's June bulletin and, for any appliance that was internet-reachable with the API enabled before it was patched, run a compromise assessment of the appliance rather than closing the ticket on the version string."
updates:
  - at: "2026-07-02T04:55:25Z"
    run_id: 2026-07-02-6551f8c2
    type: update
    summary: >
      Kemp LoadMaster exploitation now confirmed. eSentire reports in-the-wild exploitation attempts
      against the pre-auth command-injection CVE-2026-8037 began 29 June — the same day a public PoC
      dropped — though observed attempts failed (eSentire TRU).
    fields:
      - actions
      - cves
      - evidence
      - sources
      - tags
      - body
    merged_from: 2026-07-02/kemp-loadmaster-cve-2026-8037-exploitation-attempts-confirme
  - at: "2026-08-08T04:45:00Z"
    run_id: 2026-08-08T0409Z-intel
    type: update
    summary: >
      CISA added CVE-2026-8037 to its Known Exploited Vulnerabilities catalog on 2026-08-07, based on
      evidence of active exploitation of the unauthenticated command-injection flaw in Progress Kemp
      LoadMaster. When this pipeline last covered it on 2026-07-02 the only observed activity was
      exploitation attempts that eSentire reported as unsuccessful. Every LoadMaster running a version
      at or below GA 7.2.63.1, or the LTSF release 7.2.54.17, with the API enabled is affected; any
      appliance that sat internet-reachable and unpatched between the 29 June proof-of-concept and now
      warrants a compromise assessment rather than an upgrade alone.
    fields:
      - actions
      - affected_products
      - cves
      - evidence
      - sources
      - tags
      - techniques
      - body
    merged_from: 2026-08-08/cve-2026-8037-kemp-loadmaster-kev-confirmed-exploitation
migrated_from: briefs/2026-06-30.md
---

CVE-2026-8037 (CVSS 9.8) is a pre-authentication RCE in Progress Kemp LoadMaster, an edge load balancer ([watchTowr Labs, 2026-06-29](https://labs.watchtowr.com/enterprise-tech-in-shell-out-progress-kemp-loadmaster-uninitialized-heap-to-pre-auth-rce-cve-2026-8037/) · [Trend Micro ZDI, 2026-06-09](https://www.zerodayinitiative.com/advisories/ZDI-26-342/)). The `escape_quotes()` function in the `access` executable allocates buffers via uninitialized `malloc()` without null-terminating escaped strings; a sprayed JSON payload to `/accessv2` (four single-quotes expanding to 16 bytes) overwrites heap metadata in adjacent freed chunks, and the subsequent `__sprintf_chk()` reads out-of-bounds into attacker-controlled data, reaching code execution as root with no authentication. watchTowr published the full mechanics. Affected: GA ≤ 7.2.63.1 and LTSF ≤ 7.2.54.17; fixed in v7.2.63.2 (which switches to `calloc()` with proper null termination). A second bulletin CVE, CVE-2026-33691, bypasses file-upload extension checks via OWASP CRS whitespace padding. Progress reports no known active exploitation. Hardening: patch to v7.2.63.2 and restrict the management interface to a dedicated admin VLAN; perimeter anomaly detection for unusual character sequences in JSON POSTs to `/accessv2`.

## Update — 2026-07-02T04:55:25Z

ESentire's Threat Response Unit reports that in-the-wild exploitation attempts against CVE-2026-8037 — the Progress Kemp LoadMaster pre-auth OS command-injection flaw reachable through the `/accessv2` API endpoint (CVSS 9.6–9.8) — began 2026-06-29, the same day a public proof-of-concept was released, confirming the compressed PoC-to-exploitation timeline ([eSentire TRU, 2026-06-30](https://www.esentire.com/security-advisories/progress-kemp-loadmaster-vulnerability-targeted-cve-2026-8037)).

The observed attempts were unsuccessful, with no post-compromise activity, but eSentire assesses that public PoC availability plus detailed technical write-ups will drive continued and likely more successful attacks near-term ([The Hacker News, 2026-07-01](https://thehackernews.com/2026/07/latest-progress-kemp-loadmaster-pre.html)). Affected versions remain LoadMaster 7.2.63.1 and earlier (GA) and 7.2.54.17 and earlier (LTSF); Progress shipped patched firmware in early June 2026. Patch remains the primary mitigation; disabling the LoadMaster API where not required removes the `/accessv2` attack surface entirely. Hunt `/accessv2` traffic for malformed/oversized parameters and repeated probing from related sources in a short window (T1190 → T1059).

## Update — 2026-08-08T04:45:00Z

CISA added CVE-2026-8037 to its Known Exploited Vulnerabilities catalog on 2026-08-07, "based on evidence of active exploitation" ([CISA, 2026-08-07](https://www.cisa.gov/news-events/alerts/2026/08/07/cisa-adds-one-known-exploited-vulnerability-catalog)). The catalog record describes the flaw as a command injection that "allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints," classes it CWE-77, and records known ransomware-campaign use as unknown ([CISA, 2026-08-07](https://www.cisa.gov/news-events/alerts/2026/08/07/cisa-adds-one-known-exploited-vulnerability-catalog)).

The delta is the status, not the mechanics. This pipeline's 2026-07-02 entry recorded exploitation *attempts* beginning the day the proof-of-concept dropped, all of them unsuccessful with no post-compromise activity; a federal catalog entry asserting active exploitation is a different claim, arriving five weeks later. Nothing in the affected estate has changed: watchTowr Labs gives the vulnerable version range as "Kemp LoadMaster: GA v7.2.63.1 and older" together with the LTSF release v7.2.54.17 and older, in both cases only when the API is enabled ([watchTowr Labs, 2026-06-29](https://labs.watchtowr.com/enterprise-tech-in-shell-out-progress-kemp-loadmaster-uninitialized-heap-to-pre-auth-rce-cve-2026-8037/)). No authority has named an exploiting cluster or described an observed intrusion path.

The catalog's remediation due date is a US federal compliance clock and carries no weight here. What does carry weight is the interval: a public exploit has existed since late June against an appliance class that terminates traffic at the network edge, and the flaw needs nothing but reachability to the API. An organisation that patched in June is fine. An organisation that has been treating this as a scheduled item now has a gap between the PoC and its own patch date during which a working, public exploit was being fired at exposed instances.

Detection remains network-side rather than host-side, because the appliance does not normally surface process telemetry to defenders: in reverse-proxy or web-application-firewall logs in front of the management API, unauthenticated `POST` requests to the `/accessv2` endpoint carrying malformed or oversized parameters, and repeated probing of that endpoint from related sources in a short window, are the observable shape ([watchTowr Labs, 2026-06-29](https://labs.watchtowr.com/enterprise-tech-in-shell-out-progress-kemp-loadmaster-uninitialized-heap-to-pre-auth-rce-cve-2026-8037/)). **Triage:** legitimate LoadMaster API clients authenticate and send well-formed payloads from a small, stable set of management sources — the discriminators are an unauthenticated request reaching `/accessv2` at all, and parameter content that is malformed rather than merely unexpected. Hardening is unchanged and still the strongest control available: disable the LoadMaster API where it is not required, which removes the endpoint entirely, and keep the management interface off any general-purpose network.
