THE Kemp LoadMaster RCE vulnerability (CVE-2026-8037) was exploited starting June 29, 2026, coinciding with the release of proof-of-concept exploit code. This severe flaw allows unauthenticated attackers to execute commands as root, risking broader system compromise due to its placement at the network edge. The vulnerability affects versions 7.2.63.1 and earlier, with patches released on June 4. If immediate updates are not possible, disabling the LoadMaster API is recommended to mitigate the threat. Administrators should also review logs for suspicious API requests.
Kemp LoadMaster zero day RCE exploited PoC surfaces patch urged
CyberSIXT Evidence Panel
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
CISA urges patch Progress Kemp LoadMaster CVE-2026-8037 RCE flaw
cybersixt.com
-
CISA flags exploited LoadMaster bug CVE-2026-8037, urges patch
cybersixt.com
-
CISA Flags Progress LoadMaster Injection Flaw CVE-2026-8037
cybersixt.com
-
CISA Adds Critical LoadMaster Command Injection Flaw to KEV List
cybersixt.com
-
Weekly Threat Intelligence: The July 2026 Breaches
cybersixt.com
-
CVE-2026-8037: Progress Kemp LoadMaster RCE Exploited in the Wild
cybersixt.com
-
Kemp LoadMaster zero day RCE exploited PoC surfaces patch urged
securityonline.info
-
LoadMaster flaw lets attackers run root commands remotely
cybersixt.com
-
Check Point VPN, Kemp LoadMaster hit by CVE-2026-50751 exploit
cybersixt.com