INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation

| 2026-06-29 19:25 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The Canadian cybersecurity company has identified exploitation attempts targeting CVE-2026-8037, a critical operating system command injection flaw that could be exploited to achieve arbitrary code execution on susceptible devices. The vulnerability is believed to have been active in the immediate future due to the availability of proof-of-concept exploit and detailed technical specifics. Progress LoadMaster appliances are at risk, with affected versions including GA v7.2.63.1 and older, and LTSF v7.2.54.17 and older, when the API is enabled. The company has released fixed versions: GA v7.2.63.2 and LTSF v7.2.54.18 to patch this vulnerability.
Technical Mitigations AI-generated
* Regularly update and patch operating systems: Ensure that all devices, including servers and workstations, run the latest version of the operating system to prevent exploitation of known vulnerabilities like CVE-2026-8037. * Implement input validation and sanitization: Use libraries or built-in functions (like those provided by Progress Kemp LoadMaster) to validate and sanitize user-supplied input before it reaches the application. This can help prevent buffer overflows and other types of attacks that exploit improper handling of user data. * Use secure coding practices in development: Encourage developers to follow best practices for writing secure code, such as using parameterized queries or prepared statements when interacting with databases, and avoiding sensitive information like API keys from being hardcoded into the application. * Monitor network traffic and logs: Regularly monitor network traffic and system logs to detect any suspicious activity that may indicate an attack is in progress. This can help prevent attacks before they succeed by identifying potential vulnerabilities and taking prompt action to mitigate them. * Implement a secure patching strategy for vulnerable systems: When patches are available, ensure that all affected systems are patched promptly to prevent exploitation of known vulnerabilities like CVE-2026-8037.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

192.168.•••.•••
7.2.•••.•••
7.2.•••.•••
AAAAAA••••••••••••••••••••••••••
BBBBBB••••••••••••••••••••••••••
CCCCCC••••••••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2024-1212CVE-2024-1212 CVE-2026-8037CVE-2026-8037 CVE-2026-33691CVE-2026-33691
Target & Sectors
NORTH_AMERICA NORTH_AMERICA
Incident Timeline
‎November 2024
Threat actors used a previously known command injection flaw in the Progress Kemp LoadMaster to target CISA.
vulnerability CVE-2024-1212
vulnerability CVSS 10.0
attribution CISA
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
‎April 15, 2026
Threat actors exploited a Progress LoadMaster Pre-Auth RCE flaw to gain access.
‎April 2026
Progress patched five more high-severity LoadMaster flaws, including four command injection issues.
‎2026/06/01
Threat actors used a Progress LoadMaster Pre-Auth RCE flaw to exploit an OS Command Injection vulnerability in the API.
tactic Remote Code Execution
organisation LoadMaster
organisation Progress LoadMaster
‎June 4th
Progress published an advisory on June 4th about a Command Injection Remote Code Execution vulnerability in Kemp LoadMaster.
tactic Remote Code Execution
‎June 4
Progress Kemp LoadMaster was exploited on June 4.
‎June 9
Threat actors exploited a Progress Kemp LoadMaster Pre-Auth RCE flaw in the target system.
‎2026/06/29
Threat actors used a Progress Kemp LoadMaster Pre-Auth RCE flaw in versions 7.2.63.1 and older to target Kemp LoadMaster: LTSF v7.2.54.17 and older when the API is enabled.
infrastructure 2.63.1
infrastructure 2.54.17
infrastructure 7.2.63
observable 7.2.63.2
observable 7.2.63.1
‎June 29, 2026
Threat actors exploited a Progress Kemp LoadMaster Pre-Auth RCE flaw on June 29, 2026.
‎June 29
Researchers at watchTowr Labs published a detailed technical write-up on June 29 that walked through the full exploit chain of Progress Kemp LoadMaster Pre-Auth RCE flaw.
‎2026/06/29
The patch actually changed the function `getall` in Progress Kemp LoadMaster to use a secure way of constructing and executing commands, specifically by using the `system()` function with the `v2` flag. This change prevents attackers from exploiting vulnerabilities like CVE-2026-8037 (Pre-Auth RCE) and CVE-2024-1212 (OS command injection).
organisation LEGEND
organisation calloc(1u
victims 4 strlen(user_input
organisation libc_start_call_main+122
organisation Vulnerability / Network Security
organisation Progress Kemp LoadMaster
organisation eSentire
organisation Threat Response Unit (TRU
organisation SSL
organisation ┌─────────
organisation ABCD
organisation │ ├─────────┼──────────────────
organisation Pre-Auth RCE CVE-2026-8037
organisation CVE-2026
organisation API
organisation PoC
organisation IP
organisation Progress Progress Kemp LoadMaster
organisation CVSS
organisation Google
organisation Progress Kemp LoadMaster
organisation Vulnerability / API Security
infrastructure 2.63.1
infrastructure 2.54.17
organisation Affected Versions
organisation AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
organisation SIGNAL
organisation RBX
organisation -1
infrastructure 1 fips
organisation Content-Length
organisation Content-Type
infrastructure 2913 Host
organisation Shell
organisation Preemptive Exposure Management
organisation ABC
organisation HEAP
organisation LoadMaster
organisation /accessv2
organisation AAAAA
organisation External Attack Surface Management
victims 1 strlen(user_input
victims 29 strlen(user_input
data_breach 1 byte
data_breach 2 byte i[2
data_breach 3 byte
data_breach 4 byte
organisation Progress Kemp
organisation Cl0p
infrastructure 2.63.2
infrastructure 2.54.18
organisation Progress
organisation The
‎Jun 30, 2026
Threat actors exploited a previously unknown vulnerability in the Progress Kemp LoadMaster to gain unauthorized access.
‎Jul 01, 2026
Threat actors exploited a previously unknown vulnerability in the Progress Kemp LoadMaster to gain unauthorized access.
Tactical Metrics
Metrics
infrastructure
‎2.63.1
Software Version
Metrics
infrastructure
‎2.54.17
Software Version
Metrics
infrastructure
‎7.2.63
Software Version
Metrics
infrastructure
2,913
Host
Metrics
victims
4
Strlen(User_Input
Metrics
infrastructure
1
Fips
Metrics
victims
1
Strlen(User_Input
Metrics
victims
29
Strlen(User_Input
Metrics
data_breach
1
Byte
Metrics
data_breach
2
Byte I[2
Metrics
data_breach
3
Byte
Metrics
data_breach
4
Byte
Metrics
infrastructure
‎2.63.2
Software Version
Metrics
infrastructure
‎2.54.18
Software Version