AI Stories on SHORT INFO are generated & curated with AI
unverified 04 Jul, 14:13

Progress Kemp LoadMaster pre-auth RCE CVE-2026-8037 actively exploited after public PoC

Every internet-facing Progress $PRGS Kemp LoadMaster is now a target. CVE-2026-8037, a CVSS 9.6 command-injection bug, lets an unauthenticated attacker run root commands on the load balancer. Working exploit code went public June 29, and eSentire is already logging exploitation a

Every Progress Kemp LoadMaster still reachable from the internet is exposed right now. Security researchers are tracking CVE-2026-8037, an operating-system command-injection flaw rated 9.6 on the CVSS severity scale, which lets an unauthenticated attacker execute arbitrary commands as root on the load-balancing appliance. No login is required. The timeline is what makes this urgent. Progress Software $PRGS disclosed the bug on June 4. A working proof-of-concept exploit was published on June 29, and eSentire's threat team reported exploitation attempts beginning the same day. Those early attempts failed and no post-compromise activity has been observed so far, but public exploit code typically widens the pool of attackers quickly. Why a LoadMaster matters more than an average server: it sits at the network edge, distributing traffic in front of the applications an organization runs. An attacker who gains root on that box gains a position ahead of everything it protects. Administrators on affected versions should apply the vendor patch without waiting. Reported by The Hacker News and SC Media.

Published on
XBlueskyThreadsFacebook