CISA Orders Federal Agencies to Patch a Critical Kemp LoadMaster Flaw Under Active Attack
CISA added a critical, actively exploited Kemp LoadMaster command injection flaw to its must-patch catalog, giving federal agencies a same-day deadline while independent telemetry shows six weeks of...
The U.S. Cybersecurity and Infrastructure Security Agency added a critical Progress Kemp LoadMaster vulnerability to its Known Exploited Vulnerabilities catalog on August 7, giving federal civilian agencies until today, August 10, to patch it under Binding Operational Directive 26-04. The deadline, first detailed by BleepingComputer, arrives as independent telemetry shows attackers have been probing the flaw for six weeks.
Table Of Content
An Uninitialized Buffer Turns Into Pre-Auth RCE
Tracked as CVE-2026-8037 and rated 9.6 out of 10 on the CVSS scale, the flaw lets an unauthenticated attacker execute arbitrary commands on a Kemp LoadMaster appliance by exploiting unsanitized input across multiple API command endpoints, including the appliance’s /accessv2 endpoint, according to watchTowr Labs’ research. Kemp LoadMaster is a widely deployed application delivery controller and load balancer: Progress Software says 80 percent of Fortune 500 companies use its products and services, and the LoadMaster line alone has more than 100,000 deployments worldwide, including at Amazon and the U.S. Air Force, according to BleepingComputer.
A technical analysis from watchTowr Labs, published in June, traces the root cause to escape_quotes(), a function meant to sanitize input before it reaches a shell command. The function allocated its output buffer with malloc() rather than a zeroing allocator and never null-terminated the escaped string it produced. watchTowr’s researchers found that sending four single quotes as the API’s apiuser value expanded into 16 unterminated bytes that could overwrite the metadata of an adjacent freed memory chunk. By simultaneously spraying command-injection payloads across other API parameters, an attacker could get one payload to land next to that corrupted buffer, so the unterminated string read continued straight into it and executed the payload through a system() call. Progress fixed the bug in LoadMaster GA v7.2.63.2 and LTSF v7.2.54.18 by switching to a zeroing allocator and adding the missing null terminator. Versions GA v7.2.63.1 and LTSF v7.2.54.17 and earlier remain vulnerable, as does every version of Progress’s MOVEit WAF before GA v7.2.63.2.
Exploitation Has Been Running for Weeks
Progress disclosed the vulnerability and shipped a patch for it on June 4. That changed on June 29, when a functional proof-of-concept exploit went public. eSentire’s Threat Response Unit says it began detecting exploitation attempts that same day, tracing early activity to three IP addresses; in the intrusions it observed, “exploitation was not successful, and as such, no post-compromise activity was observed.”
The activity has not let up since. Threat-intelligence platform KEVIntel has logged 792 exploitation attempts over 41 days from 65 unique IP addresses in 18 countries, including Australia, China, Indonesia, Japan, Poland, and the United States, with the most recent burst of five attempts recorded on August 4, according to The Hacker News. Internet-scanning service Shadowserver counted nearly 300 Kemp LoadMaster instances still exposed online as of BleepingComputer’s report, though it could not say how many were honeypots or had already been patched.
A Federal Deadline, and a Warning for Everyone Else
BOD 26-04 formally binds only Federal Civilian Executive Branch agencies, which CISA is requiring to secure any LoadMaster or MOVEit WAF deployment by the end of today. “This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise,” CISA said in the alert accompanying the catalog addition. The directive does not bind anyone outside government, but CISA urged all defenders running an unpatched, internet-facing appliance to prioritize patching CVE-2026-8037 regardless, a call made more urgent by how many instances are still sitting exposed six weeks after working exploit code became public.








No Comment! Be the first one.