CRITICAL
Critical Pre-Auth RCE in Progress Kemp LoadMaster Lets Attackers Run Root Commands
A critical vulnerability in Progress Kemp LoadMaster, tracked as CVE-2026-8037 (CVSS 9.8), lets an unauthenticated attacker execute arbitrary commands as root on the appliance by sending a crafted request to its API, according to ZDI. Progress has published a patch. Any organization running LoadMaster with the API enabled should update immediately, since successful exploitation gives an attacker full control of the load balancer.