Edge ADC Bug Lets Unauth Caller Become the Perimeter

A LoadMaster with its API exposed can stop being a traffic manager and start being the entry point. The bug is pre-auth, so an attacker does not need valid access first; if they reach the API, they can turn the appliance that handles TLS, WAF, and routing into code execution on the edge box itself. Progress Kemp says CVE-2026-8037 affects Kemp LoadMaster GA v7.2.63.1 and older, and LTSF v7.2.54.17 and older, when the API is enabled. watchTowr’s research on 7.2.63.1 versus 7.2.63.2 shows the break sits in quote handling in the management API, where a bad input path can corrupt memory before authentication matters. That makes compromise of the ADC a perimeter breach, not a single-device event, because the attacker is inside the trust point that brokers application traffic for everything behind it.

Part of the PlainSec briefing for 2026-06-30

Sources