Kemp LoadMaster Command Injection CVE-2026-8037 Under Active Exploitation

Manish Garg
Manish Garg Associate of (ISC)² · RingSafe
Jul 6, 2026
2 min read

Attackers are actively probing and exploiting CVE-2026-8037, a critical operating-system command injection flaw in Progress Kemp LoadMaster, the load balancer and application delivery controller that fronts web applications in thousands of enterprise networks. Exploitation attempts against internet-facing LoadMaster instances have been observed in the wild, continuing this year’s relentless targeting of edge infrastructure.

Edge devices remain the softest way in

A load balancer is a uniquely privileged place to stand: it terminates TLS, sees every credential that transits it, and is trusted by everything behind it. Command injection on an ADC hands the attacker a position that EDR agents rarely cover and SOC dashboards rarely watch. This is the same pattern we analysed in our June coverage of VPN and firewall exploitation campaigns — the perimeter appliance has become the preferred first hop, precisely because it is a security blind spot.

The India angle

Kemp LoadMaster is a common sight at the edge of Indian BFSI, insurance, and mid-market enterprise networks, where it often balances the very portals that carry regulated customer data. Two consequences follow for regulated entities:

  • RBI and SEBI incident clocks — compromise of an appliance in the data path of customer transactions is a reportable cyber incident; for most covered entities that means a 6-hour window once detected.
  • Appliances are in scope, whether or not you scoped them — if your last VAPT excluded the ADC as “vendor-managed infrastructure”, your attack surface review has a hole exactly where attackers are looking.

What security teams should do now

Apply the Progress fix for CVE-2026-8037 immediately and restrict LoadMaster management interfaces to a dedicated admin network — management planes should never be internet-reachable. Review the appliance for unexpected admin users, modified templates, and outbound connections it has no business making; on an ADC those are the durable persistence mechanisms. Then rotate any credentials and certificates the device holds. Assume six months of exposure until log review proves otherwise.

Worried about your exposure?

Get a free attack-surface review

We check what an attacker would see about your business — leaked credentials, exposed services, dark-web mentions. 30 minutes, no obligation.

Book exposure review Replies in 4 working hrs · India-only · Senior consultants