Active exploitation attempts are underway against a critical Progress Kemp LoadMaster vulnerability. eSentire’s Threat Response Unit spotted the activity starting June 29.
The flaw is CVE-2026-8037 — a CVSS 9.6 OS command injection vulnerability in the API. An unauthenticated attacker can execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input. No credentials required.
WatchTowr Labs traced the root cause to a function called “escape_quotes()” in the load balancer app. It doesn’t properly null-terminate sanitized strings, leading to an out-of-bounds read into adjacent heap memory. An attacker can send crafted requests to the “/accessv2” endpoint and manipulate the heap to inject commands.
eSentire says the attempts it observed all failed — no post-compromise activity found. But a proof-of-concept exploit and detailed technical writeup are now public. That means more attacks are coming.
This is the second Kemp LoadMaster flaw to see active exploitation. CVE-2024-1212 (CVSS 10.0) was the first, another critical OS command injection bug that allowed arbitrary system command execution.
Attack IPs to watch: 192.42.116.58, 192.42.116.105, 146.70.139.154.
