Pre-Auth Root RCE in Progress Kemp LoadMaster: Patch the API Now
CVE-2026-8037 lets an unauthenticated attacker run commands as root via a crafted API request. CVSS 9.8. The vendor has shipped a fix.

Key points
- CVE-2026-8037 carries a CVSS score of 9.8 and requires no credentials to exploit.
- The vulnerable path sits before any identity check, so MFA on the admin UI offers no protection.
- LoadMasters frequently terminate TLS for downstream apps, including SAML IdPs and OIDC relying parties.
- A patch is available from Progress; restrict the management API to an admin VLAN if you haven't already.
- Treat any TLS private keys the appliance handled as compromised if the API was internet-reachable.
Another load balancer, another pre-auth root RCE.
Progress Kemp LoadMaster, the application delivery controller that fronts a lot of enterprise web traffic and, often, a lot of identity infrastructure, has a critical flaw in its management API. Tracked as CVE-2026-8037, the bug carries a CVSS of 9.8. An unauthenticated attacker can hit the API with a crafted request and execute arbitrary commands as root on the appliance.
A patch is out. If your LoadMaster API is reachable, install it.
Why doesn't MFA help here?
The vulnerable path sits in front of any identity check the appliance would normally enforce. This isn't privilege escalation from a low-privileged operator, and it isn't an authenticated admin abusing a debug endpoint. MFA on the admin UI does precisely nothing for you. The only mitigations that count are patching and not exposing the management plane to anything you wouldn't trust with a root shell.
Should you worry about the TLS risk?
LoadMaster appliances frequently sit on the edge, and their management interfaces have a long history of being one firewall rule away from the public internet. Shodan tends to find more of them than operators expect. Edge appliances with pre-auth RCE are attractive to initial-access brokers, and LoadMasters are particularly so because they often terminate TLS for downstream apps, including SAML IdPs and OIDC relying parties. That same exposure pattern appeared in our June 2026 coverage of an unauthenticated flaw in ServiceNow, where attackers pivoted deeper once they had a foothold upstream. A root shell on the box holding your TLS private keys is not a contained incident.
What to do
- Apply the vendor patch from the Progress security advisory for your LoadMaster branch.
- Restrict the management API to an admin VLAN or jump host.
- Rotate TLS private keys and shared secrets the appliance handled. If it was exposed and unpatched, treat them as burned.
- Pull access logs for the API endpoint and look for unexpected POSTs prior to patching.
No public exploit code exists at time of writing, but a 9.8 unauthenticated RCE on a widely deployed edge device doesn't stay theoretical for long. The ZDI advisory and the vendor bulletin are the authoritative references.
Patch the box. Then go look at what else is listening on its management interface.



