CVE Tools

Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts

The Hacker NewsBy The Hacker News

Reported exploitedProgress Kemp LoadMaster

Our summary

A critical Progress Kemp LoadMaster vulnerability is being actively exploited, with eSentire reporting targeting of CVE-2026-8037 (CVSS 9.6). The issue is an OS command injection in a pre-auth API path that can allow unauthenticated attackers to achieve arbitrary code execution on vulnerable appliances. Although observed exploitation attempts reportedly failed and did not progress further, the availability of proof-of-concept details may accelerate real-world attacks.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store