Critical Vulnerability in Kemp LoadMaster Appliances: 792 Exploitation Attempts Detected

Critical Kemp LoadMaster flaw CVE-2026-8037: 792 exploitation attempts detected. Unauthenticated command injection; apply patches urgently.

Critical Vulnerability in Kemp LoadMaster Appliances: 792 Exploitation Attempts Detected
Vulnerabilities

Illustrative image generated with AI

Vulnerability Added to the CISA Catalog

CISA has added CVE-2026-8037, affecting Progress Kemp LoadMaster appliances, to its Known Exploited Vulnerabilities (KEV) catalog.

The flaw has a CVSS score of 9.6 and was analyzed by watchTowr Labs in June 2026. Available evidence indicates active exploitation, although many attempts observed by eSentire were unsuccessful.

The exact affected and fixed versions have not been disclosed.

Unauthenticated Command Injection

The issue stems from improper input handling in the LoadMaster application’s escape_quotes() function and several command endpoints.

An unauthenticated remote attacker can send specially crafted requests to execute arbitrary commands. If successful, the attack can lead to direct code execution on the appliance.

The lack of an authentication requirement increases the risk for devices exposed to the Internet. A compromised LoadMaster could also provide a foothold for attacking or monitoring other systems on the network.

792 Attempts from 65 IP Addresses

According to data collected by KEVIntel, 792 exploitation attempts were observed over a 41-day period. The activity originated from 65 unique IP addresses across 18 countries, including Australia, China, Indonesia, Japan, Poland, and the United States.

The most recent activity was detected on August 4, 2026, with five attempts.

eSentire also linked the following addresses to the attacks:

  • 192.42.116[.]58
  • 192.42.116[.]105
  • 146.70.139[.]154

These indicators can help identify suspicious events in logs, but the absence of matches does not rule out a compromise.

Apply Updates as a Priority

Administrators should:

  • promptly update exposed Progress Kemp LoadMaster appliances;
  • verify the correct patch version with Progress, as release numbers have not been disclosed;
  • review logs for anomalous requests targeting command endpoints;
  • monitor the IP addresses associated with the observed activity;
  • restrict exposure of the management interface and unnecessary services wherever possible.

Agencies within the Federal Civilian Executive Branch (FCEB) must apply the fixes by August 10, 2026, as required by Binding Operational Directive (BOD) 26-04.

Read next

Sources

This article is an original reworking based on the sources below.

CVEs covered in this article

Back to home

Latest Cybersecurity News

All cybersecurity news →