INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation
| 2026-06-29 19:25 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The Canadian cybersecurity company has identified exploitation attempts targeting CVE-2026-8037, a critical operating system command injection flaw that could be exploited to achieve arbitrary code execution on susceptible devices. The vulnerability is believed to have been active in the immediate future due to the availability of proof-of-concept exploit and detailed technical specifics. Progress LoadMaster appliances are at risk, with affected versions including GA v7.2.63.1 and older, and LTSF v7.2.54.17 and older, when the API is enabled. The company has released fixed versions: GA v7.2.63.2 and LTSF v7.2.54.18 to patch this vulnerability.
Technical Mitigations AI-generated
* Regularly update and patch operating systems: Ensure that all devices, including servers and workstations, run the latest version of the operating system to prevent exploitation of known vulnerabilities like CVE-2026-8037.
* Implement input validation and sanitization: Use libraries or built-in functions (like those provided by Progress Kemp LoadMaster) to validate and sanitize user-supplied input before it reaches the application. This can help prevent buffer overflows and other types of attacks that exploit improper handling of user data.
* Use secure coding practices in development: Encourage developers to follow best practices for writing secure code, such as using parameterized queries or prepared statements when interacting with databases, and avoiding sensitive information like API keys from being hardcoded into the application.
* Monitor network traffic and logs: Regularly monitor network traffic and system logs to detect any suspicious activity that may indicate an attack is in progress. This can help prevent attacks before they succeed by identifying potential vulnerabilities and taking prompt action to mitigate them.
* Implement a secure patching strategy for vulnerable systems: When patches are available, ensure that all affected systems are patched promptly to prevent exploitation of known vulnerabilities like CVE-2026-8037.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
192.168.•••.•••
7.2.•••.•••
7.2.•••.•••
AAAAAA••••••••••••••••••••••••••
BBBBBB••••••••••••••••••••••••••
CCCCCC••••••••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2024-1212CVE-2024-1212
CVE-2026-8037CVE-2026-8037
CVE-2026-33691CVE-2026-33691
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
Incident Timeline
November 2024
Threat actors used a previously known command injection flaw in the Progress Kemp LoadMaster to target CISA.
Click on any entity below to view its context and source!
vulnerability
CVE-2024-1212
In November 2024, CISA
added a previous LoadMaster command injection flaw
(CVE-2024-1212, CVSS 10.0) to its Known Exploited Vulnerabilities catalog after confirmed exploitation in the wild.
vulnerability
CVSS 10.0
In November 2024, CISA
added a previous LoadMaster command injection flaw
(CVE-2024-1212, CVSS 10.0) to its Known Exploited Vulnerabilities catalog after confirmed exploitation in the wild.
attribution
CISA
In November 2024, CISA
added a previous LoadMaster command injection flaw
(CVE-2024-1212, CVSS 10.0) to its Known Exploited Vulnerabilities catalog after confirmed exploitation in the wild.
attribution
Known Exploited
In November 2024, CISA
added a previous LoadMaster command injection flaw
(CVE-2024-1212, CVSS 10.0) to its Known Exploited Vulnerabilities catalog after confirmed exploitation in the wild.
tactic
T1588.006 - Vulnerabilities
In November 2024, CISA
added a previous LoadMaster command injection flaw
(CVE-2024-1212, CVSS 10.0) to its Known Exploited Vulnerabilities catalog after confirmed exploitation in the wild.
April 15, 2026
Threat actors exploited a Progress LoadMaster Pre-Auth RCE flaw to gain access.
April 2026
Progress patched five more high-severity LoadMaster flaws, including four command injection issues.
2026/06/01
Threat actors used a Progress LoadMaster Pre-Auth RCE flaw to exploit an OS Command Injection vulnerability in the API.
Click on any entity below to view its context and source!
tactic
Remote Code Execution
"OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an unauthenticated attacker with permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input," Progress
said
in an advisory for the vulnerability released early last month.
organisation
LoadMaster
"OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an unauthenticated attacker with permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input," Progress
said
in an advisory for the vulnerability released early last month.
organisation
Progress LoadMaster
"OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an unauthenticated attacker with permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input," Progress
said
in an advisory for the vulnerability released early last month.
June 4th
Progress published an advisory on June 4th about a Command Injection Remote Code Execution vulnerability in Kemp LoadMaster.
Click on any entity below to view its context and source!
tactic
Remote Code Execution
On June 4th, Progress
published
an advisory about a “Command Injection Remote Code Execution Vulnerability” in Kemp LoadMaster, exploitable by the friendliest of unauthenticated attackers.
June 4
Progress Kemp LoadMaster was exploited on June 4.
June 9
Threat actors exploited a Progress Kemp LoadMaster Pre-Auth RCE flaw in the target system.
2026/06/29
Threat actors used a Progress Kemp LoadMaster Pre-Auth RCE flaw in versions 7.2.63.1 and older to target Kemp LoadMaster: LTSF v7.2.54.17 and older when the API is enabled.
Click on any entity below to view its context and source!
infrastructure
2.63.1
The vulnerability affects the following versions, when the API is enabled:
Kemp LoadMaster: GA v7.2.63.1 and older
Kemp LoadMaster: LTSF v7.2.54.17 and older
Setting The Scene
To fuel our analysis today, we compared the following versions following our normal ‘what the hell has changed’ process:
7.2.63.1 (Vulnerable)
7.2.63.2 (Different)
Let’s Dive In
We started our work on the 7.2.63.1 version, diffing the
access
executable against the 7.2.63.2:
While the changes are minimal, let’s look at the unpatched version in a little more detail:
_BYTE *__fastcall escape_quotes(const char *user_input) //
infrastructure
2.54.17
The vulnerability affects the following versions, when the API is enabled:
Kemp LoadMaster: GA v7.2.63.1 and older
Kemp LoadMaster: LTSF v7.2.54.17 and older
Setting The Scene
To fuel our analysis today, we compared the following versions following our normal ‘what the hell has changed’ process:
7.2.63.1 (Vulnerable)
7.2.63.2 (Different)
Let’s Dive In
We started our work on the 7.2.63.1 version, diffing the
access
executable against the 7.2.63.2:
While the changes are minimal, let’s look at the unpatched version in a little more detail:
_BYTE *__fastcall escape_quotes(const char *user_input) //
infrastructure
7.2.63
The vulnerability affects the following versions, when the API is enabled:
Kemp LoadMaster: GA v7.2.63.1 and older
Kemp LoadMaster: LTSF v7.2.54.17 and older
Setting The Scene
To fuel our analysis today, we compared the following versions following our normal ‘what the hell has changed’ process:
7.2.63.1 (Vulnerable)
7.2.63.2 (Different)
Let’s Dive In
We started our work on the 7.2.63.1 version, diffing the
access
executable against the 7.2.63.2:
While the changes are minimal, let’s look at the unpatched version in a little more detail:
_BYTE *__fastcall escape_quotes(const char *user_input) //
observable
7.2.63.2
The vulnerability affects the following versions, when the API is enabled:
Kemp LoadMaster: GA v7.2.63.1 and older
Kemp LoadMaster: LTSF v7.2.54.17 and older
Setting The Scene
To fuel our analysis today, we compared the following versions following our normal ‘what the hell has changed’ process:
7.2.63.1 (Vulnerable)
7.2.63.2 (Different)
Let’s Dive In
We started our work on the 7.2.63.1 version, diffing the
access
executable against the 7.2.63.2:
While the changes are minimal, let’s look at the unpatched version in a little more detail:
_BYTE *__fastcall escape_quotes(const char *user_input) //
observable
7.2.63.1
The vulnerability affects the following versions, when the API is enabled:
Kemp LoadMaster: GA v7.2.63.1 and older
Kemp LoadMaster: LTSF v7.2.54.17 and older
Setting The Scene
To fuel our analysis today, we compared the following versions following our normal ‘what the hell has changed’ process:
7.2.63.1 (Vulnerable)
7.2.63.2 (Different)
Let’s Dive In
We started our work on the 7.2.63.1 version, diffing the
access
executable against the 7.2.63.2:
While the changes are minimal, let’s look at the unpatched version in a little more detail:
_BYTE *__fastcall escape_quotes(const char *user_input) //
June 29, 2026
Threat actors exploited a Progress Kemp LoadMaster Pre-Auth RCE flaw on June 29, 2026.
June 29
Researchers at watchTowr Labs published a detailed technical write-up on June 29 that walked through the full exploit chain of Progress Kemp LoadMaster Pre-Auth RCE flaw.
2026/06/29
The patch actually changed the function `getall` in Progress Kemp LoadMaster to use a secure way of constructing and executing commands, specifically by using the `system()` function with the `v2` flag. This change prevents attackers from exploiting vulnerabilities like CVE-2026-8037 (Pre-Auth RCE) and CVE-2024-1212 (OS command injection).
Click on any entity below to view its context and source!
organisation
LEGEND
That lets us inspect the buffer directly and see exactly what is about to be printed:
pwndbg> b fprintf
Breakpoint 1 at 0x1080
pwndbg> r
Starting program: /tmp/uninit/test
LEGEND:
organisation
calloc(1u
result = user_input;
if ( v2 )
{
result = calloc(1u, 4 * (strlen(user_input) + 1)
victims
4 strlen(user_input
result = user_input;
if ( v2 )
{
result = calloc(1u, 4 * (strlen(user_input) + 1)
organisation
libc_start_call_main+122
◂— 0xfbad2084
RSI 0x555555556004 ◂— 0x3b031b01000a7325 /* '%s\n' */
───────────────────────────────────────────────────────────────────────────[ BACKTRACE ]───────────────────────────────────────────────────────────────────────────
► 0 0x7ffff7c5f560 fprintf
1 0x55555555529b main+274
2 0x7ffff7c2a1ca __libc_start_call_main+122
3 0x7ffff7c2a28b __
organisation
Vulnerability / Network Security
Ravie Lakshmanan
Jul 01, 2026
Vulnerability / Network Security
A recently disclosed critical security flaw impacting Progress Kemp LoadMaster is seeing active exploitation attempts, according to an
advisory
from eSentire's Threat Response Unit (TRU).
organisation
Progress Kemp LoadMaster
Ravie Lakshmanan
Jul 01, 2026
Vulnerability / Network Security
A recently disclosed critical security flaw impacting Progress Kemp LoadMaster is seeing active exploitation attempts, according to an
advisory
from eSentire's Threat Response Unit (TRU).
organisation
eSentire
Ravie Lakshmanan
Jul 01, 2026
Vulnerability / Network Security
A recently disclosed critical security flaw impacting Progress Kemp LoadMaster is seeing active exploitation attempts, according to an
advisory
from eSentire's Threat Response Unit (TRU).
organisation
Threat Response Unit (TRU
Ravie Lakshmanan
Jul 01, 2026
Vulnerability / Network Security
A recently disclosed critical security flaw impacting Progress Kemp LoadMaster is seeing active exploitation attempts, according to an
advisory
from eSentire's Threat Response Unit (TRU).
organisation
SSL
Typically, beyond basic load balancing, it provides Layer 4 and Layer 7 traffic management, SSL/TLS offloading, content switching, health checking, and a built-in web application firewall (WAF) to protect against common threats.
organisation
┌─────────
quote quote quote
= '\'' (4 characters)
┌─────────┬──────────────────┐
│ input │ output │
├─────────┼──────────────────┤
│ ABCD │ ABCD │
├─────────┼──────────────────┤
│ ' │ '\'' │
├─────────┼──────────────────┤
│ O'Brien │ O'\''Brien │
├─────────┼──────────────────┤
│ '''' │ '\'''\'''\'''\'' │
└─────────┴──────────────────┘
So, What Did The Patch Actually Change?
organisation
ABCD
quote quote quote
= '\'' (4 characters)
┌─────────┬──────────────────┐
│ input │ output │
├─────────┼──────────────────┤
│ ABCD │ ABCD │
├─────────┼──────────────────┤
│ ' │ '\'' │
├─────────┼──────────────────┤
│ O'Brien │ O'\''Brien │
├─────────┼──────────────────┤
│ '''' │ '\'''\'''\'''\'' │
└─────────┴──────────────────┘
So, What Did The Patch Actually Change?
organisation
│
├─────────┼──────────────────
quote quote quote
= '\'' (4 characters)
┌─────────┬──────────────────┐
│ input │ output │
├─────────┼──────────────────┤
│ ABCD │ ABCD │
├─────────┼──────────────────┤
│ ' │ '\'' │
├─────────┼──────────────────┤
│ O'Brien │ O'\''Brien │
├─────────┼──────────────────┤
│ '''' │ '\'''\'''\'''\'' │
└─────────┴──────────────────┘
So, What Did The Patch Actually Change?
organisation
Pre-Auth RCE CVE-2026-8037
Progress Kemp LoadMaster Uninitialized Heap to Pre-Auth RCE CVE-2026-8037).
organisation
CVE-2026
Edge appliances have a habit of becoming the way in rather than the thing keeping people out, and CVE-2026-8037 keeps that streak alive: a pre-authentication Remote Code Execution vulnerability accessible to anyone who can access the API.
organisation
API
Edge appliances have a habit of becoming the way in rather than the thing keeping people out, and CVE-2026-8037 keeps that streak alive: a pre-authentication Remote Code Execution vulnerability accessible to anyone who can access the API.
Swati Khandelwal
Jun 30, 2026
Vulnerability / API Security
A critical vulnerability in Progress Kemp LoadMaster can let an unauthenticated attacker execute arbitrary commands as root on the appliance by sending a crafted request to its API.
organisation
PoC
However, the availability of a proof-of-concept (PoC) exploit and detailed technical specifics is expected to drive malicious activity against CVE-2026-8037 in the immediate future.
organisation
IP
The attack attempts originate from the following IP addresses -
192.42.116[.]58
192.42.116[.]105
146.70.139[.]154
CVE-2026-8037 is the second Progress Progress Kemp LoadMaster flaw to witness active exploitation efforts after
CVE-2024-1212
(CVSS score: 10.0), another critical OS command injection vulnerability that could be abused for arbitrary system command execution.
organisation
Progress Progress Kemp LoadMaster
The attack attempts originate from the following IP addresses -
192.42.116[.]58
192.42.116[.]105
146.70.139[.]154
CVE-2026-8037 is the second Progress Progress Kemp LoadMaster flaw to witness active exploitation efforts after
CVE-2024-1212
(CVSS score: 10.0), another critical OS command injection vulnerability that could be abused for arbitrary system command execution.
organisation
CVSS
The flaw, tracked as
CVE-2026-8037
, carries a CVSS score of
9.8 according to ZDI
.
organisation
Google
A quick Google search showed this vulnerability was discovered by a researcher named
Syed Ibrahim Ahmed of TrendAI Research
with the advisory titled: “apiuser Uninitialized Memory Remote Code Execution Vulnerability”.
organisation
Progress Kemp LoadMaster
Swati Khandelwal
Jun 30, 2026
Vulnerability / API Security
A critical vulnerability in Progress Kemp LoadMaster can let an unauthenticated attacker execute arbitrary commands as root on the appliance by sending a crafted request to its API.
This time, we're looking at Progress Kemp LoadMaster, a load balancer that sits at the edge of a lot of enterprise networks.
organisation
Vulnerability / API Security
Swati Khandelwal
Jun 30, 2026
Vulnerability / API Security
A critical vulnerability in Progress Kemp LoadMaster can let an unauthenticated attacker execute arbitrary commands as root on the appliance by sending a crafted request to its API.
infrastructure
2.63.1
Affected Versions and Fix
The flaw affects LoadMaster GA v7.2.63.1 and older, and LTSF v7.2.54.17 and older, when the API is enabled.
infrastructure
2.54.17
Affected Versions and Fix
The flaw affects LoadMaster GA v7.2.63.1 and older, and LTSF v7.2.54.17 and older, when the API is enabled.
organisation
Affected Versions
Affected Versions and Fix
The flaw affects LoadMaster GA v7.2.63.1 and older, and LTSF v7.2.54.17 and older, when the API is enabled.
organisation
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
A small C program makes this much easier to explain:
#include <string.h>
#include <stdio.h>
#include <stdlib.h>
int main(int args, char **argv){
char *buf1 = malloc(0x20);
char *buf2 = malloc(0x20);
char *buf3 = malloc(0x20);
strcpy(buf1, "AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA");
strcpy(buf2, "BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB");
strcpy(buf3, "CCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCC");
free(buf1);
free(buf2);
free(buf3);
char *buf4 = malloc(0x20);
fprintf(stdout, "%s\n", buf4 );
return 0;
}
As shown in our tiny demonstration:
We allocate three buffers of size
0x20
.
organisation
SIGNAL
| WX | RODATA
──────────────────────────────────────────────────────────────────────────[ LAST SIGNAL ]──────────────────────────────────────────────────────────────────────────
Breakpoint hit at 0x7ffff7c5f560
──────────────────────────────────────────────────────[ REGISTERS / show-flags off / show-compact-regs off ]───────────────────────────────────────────────────────
RAX 0
RBX 0x7fffffffdd48 —▸ 0x7fffffffdfe6 ◂— '/tmp/uninit/test'
RCX 0x555555556004 ◂— 0x3b031b01000a7325 /* '%s\n' *
organisation
RBX
| WX | RODATA
──────────────────────────────────────────────────────────────────────────[ LAST SIGNAL ]──────────────────────────────────────────────────────────────────────────
Breakpoint hit at 0x7ffff7c5f560
──────────────────────────────────────────────────────[ REGISTERS / show-flags off / show-compact-regs off ]───────────────────────────────────────────────────────
RAX 0
RBX 0x7fffffffdd48 —▸ 0x7fffffffdfe6 ◂— '/tmp/uninit/test'
RCX 0x555555556004 ◂— 0x3b031b01000a7325 /* '%s\n' *
organisation
-1
)
return 0;
v4 = (const char *)escape_quotes(a2);
v5 = (const char *)escape_quotes(a1);
v6 = "";
if ( fips )
v6 = (const char *)&unk_46DFA8;
__sprintf_chk(a3, 1, -1, "
infrastructure
1 fips
)
return 0;
v4 = (const char *)escape_quotes(a2);
v5 = (const char *)escape_quotes(a1);
v6 = "";
if ( fips )
v6 = (const char *)&unk_46DFA8;
__sprintf_chk(a3, 1, -1, "
organisation
Content-Length
HTTP/1.1
Accept-Encoding: gzip, deflate, br
Content-Length: 2986
Host: 192.168.5.30:443
Content-Type: application/json
Accept: */*
Connection: keep-alive
{"cmd": "getall", "apiuser": "AAAAAA", "apipass": "BBBBBB"}
Under the hood, the function eventually constructs and executes the following command via
system()
:
organisation
Content-Type
HTTP/1.1
Accept-Encoding: gzip, deflate, br
Content-Length: 2986
Host: 192.168.5.30:443
Content-Type: application/json
Accept: */*
Connection: keep-alive
{"cmd": "getall", "apiuser": "AAAAAA", "apipass": "BBBBBB"}
Under the hood, the function eventually constructs and executes the following command via
system()
:
infrastructure
2913 Host
HTTP/1.1
Accept-Encoding: gzip, deflate, br
Content-Length: 2913
Host: 192.168.5.30:443
Content-Type: application/json
Accept: */*
Connection: keep-alive
{"cmd": "getall", "apiuser": "''''", "apipass": "BBBBB", "g0": "AAAAAAAAAAAAAAAA'; cat /etc/passwd #", "g1": "AAAAAAAAAAAAAAAA'; cat /etc/passwd #"
organisation
Shell
Enterprise Tech In, Shell Out
organisation
Preemptive Exposure Management
This research is a glimpse into the capabilities that power our Preemptive Exposure Management solution and get organizations ahead of inevitable in-the-wild exploitation: the
watchTowr Platform.
organisation
ABC
We tag them by filling them with our good old
ABC
.
organisation
HEAP
STACK | HEAP | CODE | DATA
organisation
LoadMaster
The following function is invoked whenever a request is made to LoadMaster’s
/accessv2
endpoint.
If you run LoadMaster with the API enabled, update now.
organisation
/accessv2
The following function is invoked whenever a request is made to LoadMaster’s
/accessv2
endpoint.
organisation
AAAAA
sh -c validuser -b -u 'AAAAA' -p 'QkJCQkI='
The
apiuser
value is passed to the
-u
argument, while
apipass
is base64-encoded and passed to
-p
.
organisation
External Attack Surface Management
The
watchTowr Platform
combines
External Attack Surface Management
and
Continuous Automated Red Teaming
to test your defenses against the vulnerabilities and techniques that matter: the ones real attackers are actually exploiting.
victims
1 strlen(user_input
(strlen(user_input) + 1) + 29); //
victims
29 strlen(user_input
(strlen(user_input) + 1) + 29); //
data_breach
1 byte
For a single quote, the loop produces the following output:
if ( v4 == "'" )
{
*i = '\''; // byte 1: '
i[1] = '\\'; // byte 2: \
i[2] = '\''; // byte 3: '
i += 3;
}
data_breach
2 byte i[2
For a single quote, the loop produces the following output:
if ( v4 == "'" )
{
*i = '\''; // byte 1: '
i[1] = '\\'; // byte 2: \
i[2] = '\''; // byte 3: '
i += 3;
}
data_breach
3 byte
For a single quote, the loop produces the following output:
if ( v4 == "'" )
{
*i = '\''; // byte 1: '
i[1] = '\\'; // byte 2: \
i[2] = '\''; // byte 3: '
i += 3;
}
data_breach
4 byte
*i = *v1++; // byte 4: ' (the original quote, copied)
organisation
Progress Kemp
Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts.
organisation
Cl0p
Progress is also the maker of MOVEit, whose 2023 vulnerabilities fueled a mass exploitation campaign by the Cl0p ransomware group.
infrastructure
2.63.2
Progress has released fixed versions: GA v7.2.63.2 and LTSF v7.2.54.18.
infrastructure
2.54.18
Progress has released fixed versions: GA v7.2.63.2 and LTSF v7.2.54.18.
organisation
Progress
Progress also patched a second, high-severity flaw in the same advisory: CVE-2026-33691, a WAF bypass where whitespace padding in filenames could circumvent file upload extension checks.
organisation
The
The
Canadian Centre for Cyber Security
has also issued an advisory urging administrators to apply the updates.
Jun 30, 2026
Threat actors exploited a previously unknown vulnerability in the Progress Kemp LoadMaster to gain unauthorized access.
Jul 01, 2026
Threat actors exploited a previously unknown vulnerability in the Progress Kemp LoadMaster to gain unauthorized access.
Tactical Metrics
Metrics
infrastructure
2.63.1
Software Version
Click for context!
The vulnerability affects the following versions, when the API is enabled:
Kemp LoadMaster: GA v7.2.63.1 and older
Kemp LoadMaster: LTSF v7.2.54.17 and older
Setting The Scene
To fuel our analysis today, we compared the following versions following…
Affected Versions and Fix
The flaw affects LoadMaster GA v7.2.63.1 and older, and LTSF v7.2.54.17 and older, when the API is enabled.
Metrics
infrastructure
2.54.17
Software Version
…y affects the following versions, when the API is enabled:
Kemp LoadMaster: GA v7.2.63.1 and older
Kemp LoadMaster: LTSF v7.2.54.17 and older
Setting The Scene
To fuel our analysis today, we compared the following versions following our normal ‘wha…
Affected Versions and Fix
The flaw affects LoadMaster GA v7.2.63.1 and older, and LTSF v7.2.54.17 and older, when the API is enabled.
Metrics
infrastructure
7.2.63
Software Version
The vulnerability affects the following versions, when the API is enabled:
Kemp LoadMaster: GA v7.2.63.1 and older
Kemp LoadMaster: LTSF v7.2.54.17 and older
Setting The Scene
To fuel our analysis today, we compared the following versions following…
Metrics
infrastructure
2,913
Host
HTTP/1.1
Accept-Encoding: gzip, deflate, br
Content-Length: 2913
Host: 192.168.5.30:443
Content-Type: application/json
Accept: */*
Connection: keep-alive
{"cmd": "getall", "apiuser": "''''", "apipass": "BBBBB", "g0": "AAAAAAAAAAAAAAAA'; cat /etc/pa…
Metrics
victims
4
Strlen(User_Input
result = user_input;
if ( v2 )
{
result = calloc(1u, 4 * (strlen(user_input) + 1)
Metrics
infrastructure
1
Fips
)
return 0;
v4 = (const char *)escape_quotes(a2);
v5 = (const char *)escape_quotes(a1);
v6 = "";
if ( fips )
v6 = (const char *)&unk_46DFA8;
__sprintf_chk(a3, 1, -1, "
Metrics
victims
1
Strlen(User_Input
(strlen(user_input) + 1) + 29); //
Metrics
victims
29
Strlen(User_Input
(strlen(user_input) + 1) + 29); //
Metrics
data_breach
1
Byte
For a single quote, the loop produces the following output:
if ( v4 == "'" )
{
*i = '\''; // byte 1: '
i[1] = '\\'; // byte 2: \
i[2] = '\''; // byte 3: '
i += 3;
}
Metrics
data_breach
2
Byte I[2
For a single quote, the loop produces the following output:
if ( v4 == "'" )
{
*i = '\''; // byte 1: '
i[1] = '\\'; // byte 2: \
i[2] = '\''; // byte 3: '
i += 3;
}
Metrics
data_breach
3
Byte
For a single quote, the loop produces the following output:
if ( v4 == "'" )
{
*i = '\''; // byte 1: '
i[1] = '\\'; // byte 2: \
i[2] = '\''; // byte 3: '
i += 3;
}
Metrics
data_breach
4
Byte
*i = *v1++; // byte 4: ' (the original quote, copied)
Metrics
infrastructure
2.63.2
Software Version
Progress has released fixed versions: GA v7.2.63.2 and LTSF v7.2.54.18.
Metrics
infrastructure
2.54.18
Software Version
Progress has released fixed versions: GA v7.2.63.2 and LTSF v7.2.54.18.
Intelligence Sources
The Hacker News
2026-06-30
Zero Day Fans
2026-06-29
The Hacker News
2026-07-01
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-07-23T06:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
43x
organisation
Identified Entity
LEGEND
entity
16x
timeline
Temporal Reference
June 4th
date
5x
infrastructure
Software Version
2.63.1
version
3x
vulnerability
Exploited CVE
CVE-2026-8037
cve
3x
victims
Strlen(User_Input
4
strlen(user_input
3x
data breach
Byte
1
byte
2x
industry
Targeted Sector
Defense
sector
2x
tactic
Cyber Operation Type
Remote Code Execution
tactic
2x
vulnerability
CVSS Score
10
score
2x
attribution
Attributing Entity
CISA
authority
Contextual Telemetry
Context Block
18 METRICS
target region
Target Country
United States
country
general metric
Fprintf Breakpoint
1
fprintf breakpoint
general metric
Layer
4
layer
general metric
Traffic Management
7
traffic management
general metric
Cve-2026
8,037
cve-2026
general metric
Buf4
0
buf4
infrastructure
Host
2,913
host
general metric
Rdx
4,343,434,343,434,343
rdx
general metric
0000000000020Ce1
555,555,559,330
0000000000020ce1
infrastructure
Fips
1
fips
data breach
Byte I[2
2
byte i[2
general metric
Bit
64
bit
general metric
+
16
+
source region
Origin Country
Canada
country
general metric
Score
10
score
general metric
Vulnerabilities
2,023
vulnerabilities
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
general metric
Khandelwal Jun
30
khandelwal jun
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.