Exploits

Progress Kemp LoadMaster Vulnerability Under Active Attack

Published  ·  6 min read

A critical severity vulnerability in the Progress Kemp LoadMaster load balancer has been added to CISA’s Known Exploited Vulnerabilities list. The addition comes after reports of in-the-wild exploits of this commonly-used load balancer.

The Progress Kemp LoadMaster vulnerability is tracked as CVE-2026-8037 and carries a CVSS score of 9.6. It is a command injection vulnerability which can potentially be exploited to carry out arbitrary code execution on vulnerable devices without authentication.

Let me explain the Progress Kemp LoadMaster Vulnerability, its workings and what administrators have to do about it.

What Is the Progress Kemp LoadMaster Vulnerability?

The Progress Kemp LoadMaster command injection vulnerability enables a attacker without authorization to run any command on the system by exploiting the flaws associated with improper user input handling in the command endpoints.

CISA described the Progress Kemp LoadMaster vulnerability as a command injection flaw that "allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints."

The source of the vulnerability in Progress Kemp LoadMaster was discovered in a report released in June 2026 by watchTowr Labs. This particular vulnerability is due to a certain “escape_quotes()” function in the load balancer application.Inappropriate processing of user inputs contributed significantly to the success of command injection.

The successful exploitation of the vulnerability present in the Progress Kemp LoadMaster results in an attacker being able to execute any arbitrary command without needing valid credentials. This makes it a particularly dangerous vulnerability.

Active Exploitation Observed

The Progress Kemp LoadMaster vulnerability is being actively exploited in the wild. eSentire reported in June that it was seeing active exploitation efforts targeting the flaw, although it noted those efforts were largely unsuccessful.

The attacks originated from the following IP addresses, according to eSentire:

  • 192.42.116[.]58
  • 192.42.116[.]105
  • 146.70.139[.]154

According to the telemetry data captured by KEVIntel, the following numbers represent the magnitude of the attack of the Progress Kemp LoadMaster vulnerability. During the past 41 days, there were 792 exploitation attempts originating from 65 unique IP addresses across 18 countries. The countries experiencing the issue include Australia, China, Indonesia, Japan, Poland, and the USA.

The most recent exploitation attempt was recorded on August 4, 2026. During this incident, five attacks were identified, which demonstrates that the vulnerability of the Progress Kemp LoadMaster is still being exploited.

CISA Adds to KEV Catalog

CISA added the Progress Kemp LoadMaster vulnerability to its Known Exploited Vulnerabilities catalog on Friday. This action reflects the active exploitation observed in the wild.

The addition means that Federal Civilian Executive Branch agencies are required to apply the necessary patches by August 10, 2026. This is in accordance with Binding Operational Directive 26-04.

In the case of organizations other than the federal government, the inclusion of the KEV provides a very strong indication that the Progress Kemp LoadMaster vulnerability is a high-priority issue because of its exploitation.

Technical Details

Progress Kemp LoadMaster Vulnerability is present in the “escape_quotes()” function within the load balancing application. It is caused by improper handling of user supplied input, which enables the execution of arbitrary commands.

This vulnerability is exploitable from many command endpoints, thereby resulting in an extensive attack surface. The attacker can make use of this Progress Kemp LoadMaster vulnerability without authenticating themselves.

The CVSS rating of 9.6 signifies the importance of the Progress Kemp LoadMaster vulnerability. This is because this vulnerability is exploitable without any authentication as well as allows for arbitrary code execution.

What Administrators Should Do

The Progress Kemp LoadMaster vulnerability requires immediate action from organizations using the affected product. Administrators should apply the necessary patches as soon as possible.

August 10, 2026, is the deadline for the federal agencies. It is also advised for non-federal organizations to give priority to the Progress Kemp LoadMaster vulnerability due to the ongoing exploitation of it.

Apart from fixing the vulnerability, companies need to analyze their logs for evidence of any exploitation attempt. The attacker IPs revealed by eSentire can help in this regard.

The Broader Context

The Progress Kemp LoadMaster vulnerability is the latest in a series of critical vulnerabilities affecting network infrastructure products. Load balancers are particularly interesting targets since they lie at the periphery of the network and may also be granted special access privileges.

The exploitation of the Progress Kemp LoadMaster vulnerability is a case in point, demonstrating the need for prompt patching. The attackers are already actively exploiting the vulnerability.  Organizations that postpone the patching process face considerable risks.

Wrapping It Up

The Progress Kemp LoadMaster vulnerability is a critical command injection flaw that is being actively exploited in the wild. CVE-2026-8037 allows unauthenticated attackers to execute arbitrary commands on affected appliances.

CISA has added the Progress Kemp LoadMaster vulnerability to its Known Exploited Vulnerabilities catalog. Federal agencies have until August 10, 2026, to apply patches.

Exploitation attempt has been seen coming from 65 different IPs from 18 different countries. The number of exploitation attempts in the last 41 days was 792.

Organizations using Progress Kemp LoadMaster should apply patches immediately. Review logs for signs of exploitation and use the known attacker IP addresses for threat hunting. The Progress Kemp LoadMaster vulnerability is a clear and present danger.

FAQ Section

What is the Progress Kemp LoadMaster vulnerability?

CVE-2026-8037 represents a very severe vulnerability of Progress Kemp LoadMaster that can be exploited to perform arbitrary command execution without any type of authentication.

Is the Progress Kemp LoadMaster vulnerability being actively exploited?

Yes. As per the exploit reports, the CISA has listed the vulnerability as part of the Known Exploited Vulnerabilities list. eSentire found instances of exploitation in June and stated that there were 792 such exploits in 41 days.

CVSS Score of CVE-2026-8037

The CVSS score of the vulnerability is 9.6, due to the high severity of the threat and its unauthenticated access with arbitrary code execution.

What steps should be taken by organizations?

Patches need to be applied as soon as possible. For federal agencies, there is an end date of August 10, 2026. Check logs for any exploitation signs using attacker’s IP addresses for hunting threats.

From which IP addresses were attacks launched?

The attacks originated from IP addresses such as 192.42.116[.]58, 192.42.116[.]105, and 146.70.139[.]154. A total of 65 unique IP addresses from 18 countries have been observed.

Source: The Hacker News
Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067