CVE-2026-8037
- CVSS
- —
- EPSS
- 0.774 (99.5th percentile)
- CISA KEV
- Added 2026-08-07, due 2026-08-10
- Exploitation
- No report
- Public exploits
- 2 repositories
- State
- Unknown
Coverage
Actively exploitedCritical 85Zero Day Initiative — published
ZDI-26-646: Progress Software Kemp LoadMaster escape_quotes Uninitialized Memory Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Progress Software Kemp LoadMaster. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-8037.
Actively exploitedCritical 85CISA advisories & alerts
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-8037 Progress LoadMaster Command Injection Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses…

Actively exploitedCritical 85watchTowr Labs
Enterprise Tech In, Shell Out (Progress Kemp LoadMaster Uninitialized Heap to Pre-Auth RCE CVE-2026-8037)
Welcome back to another watchTowr Labs blog post. This time, we're looking at Progress Kemp LoadMaster, a load balancer that sits at the edge of a lot of enterprise networks. Edge appliances have a habit of becoming the way in rather than the thing keeping people out, and
What we observed
- poc publishedpoc-in-github
- poc publishedpoc-in-github
- poc publishedpoc-in-github
- kev addedcisa-kev