CRITICAL
Critical Progress Kemp LoadMaster Flaw (CVE-2026-8037) Allows Pre-Auth Root RCE
Progress disclosed CVE-2026-8037, a critical vulnerability (CVSS 9.8 per ZDI) in Kemp LoadMaster that allows an unauthenticated attacker to execute arbitrary commands as root by sending a crafted request to the appliance’s API. A patch is available. Organizations running LoadMaster with the API enabled should update immediately.