en
CVE-2026-8037: Progress Kemp LoadMaster Pre-Auth RCE — escape_quotes() Heap Failure, Active Exploitation
CVE-2026-8037 (CVSS 9.6) is a pre-auth OS command injection in Kemp LoadMaster rooted in escape_quotes() heap mishandling. watchTowr published a full PoC June 29; exploitation began the same day.