CVE Tools

Enterprise Tech In, Shell Out (Progress Kemp LoadMaster Uninitialized Heap to Pre-Auth RCE CVE-2026-8037)

watchTowr LabsBy Sina Kheirkhah (@SinSinology)15 min read

ResearchKemp LoadMaster
Read at watchTowr Labs

Below is the opening; the full story is at watchTowr Labs.

From watchTowr Labs

Welcome back to another watchTowr Labs blog post.

This time, we're looking at Progress Kemp LoadMaster, a load balancer that sits at the edge of a lot of enterprise networks. Edge appliances have a habit of becoming the way in rather than the thing keeping people out, and CVE-2026-8037 keeps that streak alive: a pre-authentication Remote Code Execution vulnerability accessible to anyone who can access the API.…

Continue at watchTowr Labs

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store