CVE Tools

Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth

The Hacker NewsBy The Hacker News

PoC publicKemp LoadMaster

Our summary

Progress Kemp LoadMaster discloses a critical pre-auth remote command execution issue in its API that can allow an unauthenticated attacker to run arbitrary commands as root by sending a crafted request. The vulnerability is tracked as CVE-2026-8037 (CVSS 9.8) and affects LoadMaster GA v7.2.63.1 and older, plus LTSF v7.2.54.17 and older when the API is enabled; fixed releases are GA v7.2.63.2 and LTSF v7.2.54.18. The bug matters because the affected /accessv2 endpoint is reachable before authentication, and a public proof of concept has been demonstrated even though no exploitation reports have been made.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store