PROGRESS has identified and fixed five high-severity vulnerabilities in Kemp LoadMaster, detailed in a July 2026 bulletin. The vulnerabilities include three that allow OS command injection and two that permit privilege escalation, posing a risk of full system compromise. All require authenticated access, limiting the risk of remote exploitation. Affected versions are v7.2.63.2 and earlier for GA and LTSF, and v7.1.35.15 and earlier for Multi-Tenant systems. Users are advised to upgrade to the latest versions immediately to mitigate risks.
Progress patches critical flaws in Kemp LoadMaster load balancer
CyberSIXT Evidence Panel
Primary Source
community.progress.com
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
CISA urges patch Progress Kemp LoadMaster CVE-2026-8037 RCE flaw
securityweek.com
-
CISA flags exploited LoadMaster bug CVE-2026-8037, urges patch
securityaffairs.com
-
LoadMaster flaw leads to 792 exploit attempts, added to CISA KEV
thehackernews.com
-
CISA Adds Critical LoadMaster Command Injection Flaw to KEV List
cisa.gov
-
Progress patches critical flaws in Kemp LoadMaster load balancer
securityonline.info