CVE-2026-8037: Progress Kemp LoadMaster Pre-Auth RCE — escape_quotes() Heap Failure, Active Exploitation
CVE-2026-8037 (CVSS 9.6) is a pre-auth OS command injection in Kemp LoadMaster rooted in escape_quotes() heap mishandling. watchTowr published a full PoC June 29; exploitation began the same day.
This post is part of the Week of July 3, 2026 Security Roundup.
Vulnerability Overview
CVE-2026-8037 (CVSS 9.6) is a pre-authentication OS command injection vulnerability in Progress Kemp LoadMaster, a widely deployed application delivery controller and load balancer. watchTowr Labs published a full root cause analysis and proof-of-concept on June 29, 2026; eSentire TRU confirmed active exploitation attempts commenced the same day.
Affected Versions
- General Availability (GA): ≤ v7.2.63.1 → Fixed in v7.2.63.2
- Long-Term Support / Feature (LTSF): ≤ v7.2.54.17 → Fixed in v7.2.54.18
- Condition: LoadMaster API must be enabled (default on many deployments)
Root Cause — escape_quotes() Uninitialized Heap
The vulnerability originates in a C function named escape_quotes() in LoadMaster's API request processing stack. This function is intended to escape shell metacharacters in user-supplied values before they are passed to OS-level commands. The implementation bug:
escape_quotes()writes its sanitized output into a fixed-size heap buffer.- When the input contains specific byte sequences, the function fails to null-terminate its output string — a classic off-by-one / missing terminator pattern.
- When the result is later read as a C string, processing continues into adjacent heap memory, reading attacker-influenced data beyond the intended boundary.
- Under attacker-controllable heap layout conditions (tunable via request sizing), adjacent heap regions contain attacker-supplied content including shell metacharacters that survive the "sanitization" step.
The vulnerable API endpoint is /accessv2. The LoadMaster API service runs as root, so there is no privilege escalation step after successful command injection.
watchTowr PoC Summary
watchTowr's June 29 write-up titled "Enterprise Tech In, Shell Out" demonstrates the full exploit chain against LoadMaster GA v7.2.63.1. The PoC shows:
- An unauthenticated HTTP POST to
/accessv2with a crafted payload targeting theescape_quotes()heap layout. - Shell metacharacters surviving sanitization and being passed to a
system()-equivalent call. - Root shell execution confirmed via
idandwhoamioutput in the HTTP response.
Exploitation Timeline
- Early June 2026 — Progress patches CVE-2026-8037 in LoadMaster v7.2.63.2 / v7.2.54.18
- June 29, 2026 — watchTowr Labs publishes full analysis and PoC
- June 29, 2026 — eSentire TRU observes first active exploitation attempts within hours of PoC publication
- July 1–2, 2026 — Widening exploitation campaign confirmed by SC Media and THN
Exposure Assessment
LoadMaster is commonly deployed as an internet-facing load balancer with the management API enabled. Shodan searches for Kemp LoadMaster banners reveal thousands of publicly accessible management interfaces.
# Shodan — exposed LoadMaster management
http.title:"LoadMaster" port:443
# FOFA equivalent
title="Kemp Technologies LoadMaster"
# Check if your LoadMaster API is enabled and exposed
curl -k -s -o /dev/null -w "%{http_code}" https://loadmaster.yourdomain.com/accessv2
# Returns 200 = API exposed and listening
# Returns 403/404 = restricted or disabled
Remediation
# Option 1 — Patch (strongly preferred)
# Upgrade via LoadMaster UI:
# System Configuration → System Administration → Update Software
# Download: https://support.kemptechnologies.com/
# Option 2 — Disable API (immediate mitigation if patching is delayed)
# LoadMaster UI: System Configuration → API Security → Disable WUI API
# Via CLI (if SSH access is available):
/usr/local/bin/lmcli set api/enabled 0
# Option 3 — Restrict /accessv2 to management subnet (defense-in-depth)
# LoadMaster UI: System Configuration → Firewall Options → Source IP Restriction
# Add ACL allowing only your management subnet to /accessv2
# Verify API is disabled
curl -k -s https://loadmaster.internal/accessv2
# Should return connection refused or 403 after disabling
Detection
# LoadMaster access log — unexpected POSTs to /accessv2
grep "POST.*accessv2" /var/log/httpd/access_log | awk '$9 != "200" {print}' | tail -100
# Unexpected processes spawned by LoadMaster API service
# Enable Linux process auditing:
auditctl -a always,exit -F arch=b64 -S execve -F ppid=$(pgrep -f "loadmaster_api" | head -1) -k lm_exec
ausearch -k lm_exec --start today
# Check for new files in /tmp or /var/tmp (common staging area)
find /tmp /var/tmp -newer /etc/passwd -type f -ls