CVE-2026-8037
Pre-auth OS command injection in the LoadMaster API (/accessv2) -> arbitrary command execution on the appliance (CVSS 9.6)
- Severity
- critical
- Affected product
- Progress Kemp LoadMaster
- Affected versions
- Progress Kemp LoadMaster all versions before the fix
- CISA KEV
- Listed as a known exploited vulnerability
- EPSS
- 99% chance of exploitation in the next 30 days
- Added to NewScan
- 2026-08-08
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the Progress Kemp LoadMaster appliance and reports this CVE when the detected version falls inside the affected range below.
Added to CISA KEV 2026-08; BOD 26-04 federal remediation date 2026-08-10. eSentire telemetry: 792 exploitation attempts from 65 unique IPs across 18 countries in 41 days as of 2026-08-04. EPSS 0.993 (99.9th percentile), read from FIRST's 2026-08-08T12:02Z model run, not estimated - the api.first.org query still served the 2026-08-07 run at 0.848 that morning, so read the bulk feed's score_date before quoting a number. Unsanitised input reaches a shell through escape_quotes() in the command endpoints; POST /accessv2 with a JSON cmd body is the exploited path. Affected per NVD CPE: LoadMaster < 7.2.54.18 (LTSF) and 7.2.55.0 <= v < 7.2.63.2 (GA), plus ECS Connection Manager / Connection Manager for ObjectScale < 7.2.63.2. Deliberately NOT version-gated: the WUI hands an anonymous caller no build number, so there is nothing to compare an `lt` against and a gate would be dead data. Advisory observation until an anonymous version source exists - same stance as Citrix CVE-2025-5777 above.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →