CVE-2026-8037: Progress Kemp LoadMaster Pre-Auth RCE — escape_quotes() Heap Failure, Active Exploitation

CVE-2026-8037 (CVSS 9.6) is a pre-auth OS command injection in Kemp LoadMaster rooted in escape_quotes() heap mishandling. watchTowr published a full PoC June 29; exploitation began the same day.

CVE-2026-8037: Progress Kemp LoadMaster Pre-Auth RCE — escape_quotes() Heap Failure, Active Exploitation

This post is part of the Week of July 3, 2026 Security Roundup.

Vulnerability Overview

CVE-2026-8037 (CVSS 9.6) is a pre-authentication OS command injection vulnerability in Progress Kemp LoadMaster, a widely deployed application delivery controller and load balancer. watchTowr Labs published a full root cause analysis and proof-of-concept on June 29, 2026; eSentire TRU confirmed active exploitation attempts commenced the same day.

Affected Versions

  • General Availability (GA): ≤ v7.2.63.1 → Fixed in v7.2.63.2
  • Long-Term Support / Feature (LTSF): ≤ v7.2.54.17 → Fixed in v7.2.54.18
  • Condition: LoadMaster API must be enabled (default on many deployments)

Root Cause — escape_quotes() Uninitialized Heap

The vulnerability originates in a C function named escape_quotes() in LoadMaster's API request processing stack. This function is intended to escape shell metacharacters in user-supplied values before they are passed to OS-level commands. The implementation bug:

  1. escape_quotes() writes its sanitized output into a fixed-size heap buffer.
  2. When the input contains specific byte sequences, the function fails to null-terminate its output string — a classic off-by-one / missing terminator pattern.
  3. When the result is later read as a C string, processing continues into adjacent heap memory, reading attacker-influenced data beyond the intended boundary.
  4. Under attacker-controllable heap layout conditions (tunable via request sizing), adjacent heap regions contain attacker-supplied content including shell metacharacters that survive the "sanitization" step.

The vulnerable API endpoint is /accessv2. The LoadMaster API service runs as root, so there is no privilege escalation step after successful command injection.

watchTowr PoC Summary

watchTowr's June 29 write-up titled "Enterprise Tech In, Shell Out" demonstrates the full exploit chain against LoadMaster GA v7.2.63.1. The PoC shows:

  1. An unauthenticated HTTP POST to /accessv2 with a crafted payload targeting the escape_quotes() heap layout.
  2. Shell metacharacters surviving sanitization and being passed to a system()-equivalent call.
  3. Root shell execution confirmed via id and whoami output in the HTTP response.

Exploitation Timeline

  • Early June 2026 — Progress patches CVE-2026-8037 in LoadMaster v7.2.63.2 / v7.2.54.18
  • June 29, 2026 — watchTowr Labs publishes full analysis and PoC
  • June 29, 2026 — eSentire TRU observes first active exploitation attempts within hours of PoC publication
  • July 1–2, 2026 — Widening exploitation campaign confirmed by SC Media and THN

Exposure Assessment

LoadMaster is commonly deployed as an internet-facing load balancer with the management API enabled. Shodan searches for Kemp LoadMaster banners reveal thousands of publicly accessible management interfaces.

# Shodan — exposed LoadMaster management
http.title:"LoadMaster" port:443

# FOFA equivalent
title="Kemp Technologies LoadMaster"

# Check if your LoadMaster API is enabled and exposed
curl -k -s -o /dev/null -w "%{http_code}" https://loadmaster.yourdomain.com/accessv2
# Returns 200 = API exposed and listening
# Returns 403/404 = restricted or disabled

Remediation

# Option 1 — Patch (strongly preferred)
# Upgrade via LoadMaster UI:
# System Configuration → System Administration → Update Software
# Download: https://support.kemptechnologies.com/

# Option 2 — Disable API (immediate mitigation if patching is delayed)
# LoadMaster UI: System Configuration → API Security → Disable WUI API
# Via CLI (if SSH access is available):
/usr/local/bin/lmcli set api/enabled 0

# Option 3 — Restrict /accessv2 to management subnet (defense-in-depth)
# LoadMaster UI: System Configuration → Firewall Options → Source IP Restriction
# Add ACL allowing only your management subnet to /accessv2

# Verify API is disabled
curl -k -s https://loadmaster.internal/accessv2
# Should return connection refused or 403 after disabling

Detection

# LoadMaster access log — unexpected POSTs to /accessv2
grep "POST.*accessv2" /var/log/httpd/access_log |   awk '$9 != "200" {print}' | tail -100

# Unexpected processes spawned by LoadMaster API service
# Enable Linux process auditing:
auditctl -a always,exit -F arch=b64 -S execve   -F ppid=$(pgrep -f "loadmaster_api" | head -1) -k lm_exec
ausearch -k lm_exec --start today

# Check for new files in /tmp or /var/tmp (common staging area)
find /tmp /var/tmp -newer /etc/passwd -type f -ls

Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther