Post
CRITICAL

Critical Progress Kemp LoadMaster Flaw (CVE-2026-8037) Allows Pre-Auth Root RCE

· rce · cve · vulnerability

Progress disclosed CVE-2026-8037, a critical vulnerability (CVSS 9.8 per ZDI) in Kemp LoadMaster that allows an unauthenticated attacker to execute arbitrary commands as root by sending a crafted request to the appliance’s API. A patch is available. Organizations running LoadMaster with the API enabled should update immediately.