Critical Vulnerability in Kemp LoadMaster Appliances: 792 Exploitation Attempts Detected
Critical Kemp LoadMaster flaw CVE-2026-8037: 792 exploitation attempts detected. Unauthenticated command injection; apply patches urgently.
Illustrative image generated with AI
Vulnerability Added to the CISA Catalog
CISA has added CVE-2026-8037, affecting Progress Kemp LoadMaster appliances, to its Known Exploited Vulnerabilities (KEV) catalog.
The flaw has a CVSS score of 9.6 and was analyzed by watchTowr Labs in June 2026. Available evidence indicates active exploitation, although many attempts observed by eSentire were unsuccessful.
The exact affected and fixed versions have not been disclosed.
Unauthenticated Command Injection
The issue stems from improper input handling in the LoadMaster application’s escape_quotes() function and several command endpoints.
An unauthenticated remote attacker can send specially crafted requests to execute arbitrary commands. If successful, the attack can lead to direct code execution on the appliance.
The lack of an authentication requirement increases the risk for devices exposed to the Internet. A compromised LoadMaster could also provide a foothold for attacking or monitoring other systems on the network.
792 Attempts from 65 IP Addresses
According to data collected by KEVIntel, 792 exploitation attempts were observed over a 41-day period. The activity originated from 65 unique IP addresses across 18 countries, including Australia, China, Indonesia, Japan, Poland, and the United States.
The most recent activity was detected on August 4, 2026, with five attempts.
eSentire also linked the following addresses to the attacks:
192.42.116[.]58192.42.116[.]105146.70.139[.]154
These indicators can help identify suspicious events in logs, but the absence of matches does not rule out a compromise.
Apply Updates as a Priority
Administrators should:
- promptly update exposed Progress Kemp LoadMaster appliances;
- verify the correct patch version with Progress, as release numbers have not been disclosed;
- review logs for anomalous requests targeting command endpoints;
- monitor the IP addresses associated with the observed activity;
- restrict exposure of the management interface and unnecessary services wherever possible.
Agencies within the Federal Civilian Executive Branch (FCEB) must apply the fixes by August 10, 2026, as required by Binding Operational Directive (BOD) 26-04.
Sources
This article is an original reworking based on the sources below.




