LoadMaster Auth Bug Ends in Root Control

Progress Software’s Kemp LoadMaster has a critical authenticated remote code execution flaw, CVE-2026-8037, that can hand an attacker root on the appliance. The Zero Day Initiative says Progress has issued an update, and the issue is now on CISA’s Known Exploited Vulnerabilities list. The bug sits in LoadMaster’s escape_quotes function, where uninitialized memory is read before it is properly set up. Once a logged-in attacker reaches that code path, they can steer execution into running commands as root, so a stolen or reused admin login becomes a full appliance takeover rather than a limited app bug. That matters most where LoadMaster fronts other services: compromise at the traffic layer can put the protected systems behind it in reach. For shops that share admin access or expose it remotely, the durable exposure is the privileged credential itself, not just the binary that got patched.

Part of the PlainSec briefing for 2026-09-09

Every edition of this story: LoadMaster Auth Bug Ends in Root Control

CVEs

Sources