Threat reportVulnerabilityTL-2026-1045
CVE-2026-8037: Pre-Auth Command Injection RCE in Progress Kemp LoadMaster via Uninitialized-Heap escape_quotes() Flaw on /accessv2
CVE-2026-8037 (TL-2026-1045), also tracked as apiuser Uninitialized Memory RCE Vulnerability, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-07-01 and last reviewed 2026-08-08. It has no confirmed attribution, affects Progress Software / Kemp Kemp LoadMaster (GA), references 3 CVEs (CVE-2026-8037, CVE-2026-33691, CVE-2024-1212), maps to 21 MITRE ATT&CK techniques (T1005, T1027.010, T1036), and is covered by 9 detection rules and 33 indicators of compromise.
- CVSS
- 9.8/10Critical
- CVEs
- 3Referenced vulnerabilities
- Techniques
- 21MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 33Indicators of compromise
Key facts for TL-2026-1045
- Threat ID
- TL-2026-1045
- Also known as
- apiuser Uninitialized Memory RCE Vulnerability, ZDI-26-342
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- all sectors using edge adc load-balancer infrastructure, enterprise network infrastructure, government administration, finance, health, technology
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 33
- Updates
- 2026-08-08 · 3 updates · revalidated 3× · latest source
How CVE-2026-8037 works
A critical unauthenticated OS command injection vulnerability (CVE-2026-8037, CVSS 9.8) in Progress Kemp LoadMaster's escape_quotes() sanitization routine allows an attacker to spray heap memory via the /accessv2 API endpoint's apiuser parameter, triggering an out-of-bounds read that smuggles a shell command into a system() call and yields root-level remote code execution. eSentire's Threat Response Unit observed exploitation attempts beginning June 29, 2026 that failed, but public PoC-quality technical writeups (watchTowr Labs) published the same day are expected to accelerate weaponized attacks against Internet-facing LoadMaster API endpoints.
CVE-2026-8037 is a pre-authentication remote code execution vulnerability in Progress Kemp LoadMaster, a widely deployed application delivery controller (ADC) / load balancer appliance. The root cause lies in the internal escape_quotes() function used to sanitize the apiuser and apipass parameters accepted by the /accessv2 API endpoint before they are concatenated into a shell command string ("validuser -b %s -u '%s' -p '%s'") and executed via system(). The vulnerable escape_quotes() implementation allocated its output buffer with malloc() (leaving it uninitialized) rather than calloc(), and — critically — failed to write a trailing NUL terminator after the escaped string was generated. escape_quotes() expands each embedded single-quote character into a four-byte sequence (\'\') to prevent shell metacharacter breakout; because heap allocations are not automatically zeroed and the function never terminates its output, a subsequent internal __sprintf_chk()/sprintf() call that consumes the escaped buffer can read past the intended end of the buffer and continue copying whatever bytes happen to sit in the adjacent heap chunk into the command line that is ultimately handed to system().
Researchers at watchTowr Labs (in coordination with the original discoverer, Syed Ibrahim Ahmed of TrendAI Research, working through Trend Micro's Zero Day Initiative as ZDI-26-342) demonstrated a full pre-auth exploit chain built on this primitive: the attacker first sends a crafted /accessv2 JSON request body containing dozens of extraneous key/value pairs whose values embed a shell command injection payload (e.g. "; cat /etc/passwd #") — a heap-spray technique intended to reliably place attacker-controlled bytes in memory adjacent to the buffer that will be under-terminated. The apiuser field is then populated with a value containing four single-quote characters, which escape_quotes() expands to sixteen bytes without a terminator, causing the adjacent, attacker-sprayed heap content to be read and copied into the command string built for system(). Because the composed command is executed as root via system(), the injected shell metacharacters and command execute with full root privileges on the appliance, with no authentication required and no user interaction.
The flaw affects LoadMaster GA v7.2.63.1 and earlier and LoadMaster LTSF v7.2.54.17 and earlier, when the device's management API is enabled (the default configuration on many deployments that use LoadMaster's REST API for automation). Progress fixed the issue in GA v7.2.63.2 and LTSF v7.2.54.18 by switching escape_quotes() to use calloc() (zero-initializing the buffer) and by explicitly writing a NUL terminator (*end = 0) after the escaped output. The fix was released as part of the Progress "LoadMaster Critical Security Bulletin — June 2026," alongside a related vulnerability, CVE-2026-33691, in the same LoadMaster API/UI component.
Progress originally reported (as of its June 4, 2026 advisory) no evidence of exploitation in the wild. That changed on June 29, 2026, when eSentire's Threat Response Unit (TRU) observed opportunistic scanning and exploitation attempts against the /accessv2 endpoint from three distinct source IPs; eSentire assessed the observed attempts as unsuccessful, noting no post-compromise activity resulted. However, watchTowr Labs' detailed public technical writeup — published the same week — walks through the full exploit chain (heap spray construction, quote-expansion math, and the sprintf/system() sink) in enough depth to substantially lower the bar for independent weaponization, and defenders should treat this as imminent-exploitation-risk infrastructure requiring urgent patching or compensating controls (disabling or firewalling the LoadMaster API) rather than a theoretical bug. LoadMaster's predecessor OS command injection vulnerability in the same API surface, CVE-2024-1212 (CVSS 10.0), was also actively exploited after disclosure, reinforcing that Kemp LoadMaster's API endpoints are a recurring target for command-injection-class attacks against edge network appliances.
MITRE ATT&CK techniques used in TL-2026-1045
Collection
Defense Evasion
T1027.010 Command Obfuscation; T1036 Masquerading; T1055 Process Injection; T1211 Exploitation for Stealth
Execution
T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Command and Control
T1071 Application Layer Protocol
Discovery
T1082 System Information Discovery; T1083 File and Directory Discovery; T1087.001 Local Account
Initial Access
T1190 Exploit Public-Facing Application
Impact
Persistence
T1505 Server Software Component
Credential Access
Resource Development
T1587 Develop Capabilities; T1588.005 Exploits; T1588.006 Vulnerabilities
Reconnaissance
Affected products and versions in CVE-2026-8037
- Progress Software / Kemp — Kemp LoadMaster (GA)
Vulnerable versions: <=7.2.63.1
Fixed in: 7.2.63.2 - Progress Software / Kemp — Kemp LoadMaster (LTSF)
Vulnerable versions: <=7.2.54.17
Fixed in: 7.2.54.18
Remediation for CVE-2026-8037
Patches
- Upgrade LoadMaster GA to v7.2.63.2 or later
- Upgrade LoadMaster LTSF to v7.2.54.18 or later
- Apply the Progress 'LoadMaster Critical Security Bulletin — June 2026' which also addresses CVE-2026-33691
Immediate actions
- Restrict or disable the LoadMaster management API from untrusted/Internet-facing networks
- Place LoadMaster API endpoints behind an allowlist/VPN or management-network-only access
- Monitor /accessv2 endpoint access logs for anomalous JSON bodies with excessive key-value pairs or embedded shell metacharacters
- Block or rate-limit requests to /accessv2 from unexpected source IPs
Workarounds
- Disable the LoadMaster REST/management API entirely if automation via API is not required
- Restrict API access to a dedicated management VLAN/jump host with strict firewall ACLs
Longer-term hardening
- Establish a regular patch cadence for LoadMaster firmware given repeated history of API-facing command injection flaws (CVE-2024-1212, CVE-2026-8037)
- Deploy network-layer WAF/IPS signatures for LoadMaster API command-injection patterns
- Segment ADC/load-balancer management interfaces from general network access as a standing architecture control
- Enable centralized logging/SIEM ingestion of LoadMaster API access and system() invocation audit trails where supported
CVEs associated with CVE-2026-8037
Weaknesses (CWE) in CVE-2026-8037
CWE-78, CWE-908, CWE-170, CWE-122, CWE-787, CWE-180, CWE-77, CWE-457, CWE-125, CWE-20
Timeline of CVE-2026-8037
- Syed Ibrahim Ahmed of TrendAI Research reports the escape_quotes() heap/null-termination flaw in Kemp LoadMaster's /accessv2 endpoint to Progress via the Zero Day Initiative.
- NVD publishes the CVE-2026-8037 record (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, base score 9.6, CWE-77), classifying the attack vector as Adjacent Network with scope-changed impact.
- Progress publishes its advisory and patched versions (GA 7.2.63.2, LTSF 7.2.54.18) as part of the LoadMaster Critical Security Bulletin — June 2026, alongside CVE-2026-33691; no exploitation observed at the time.
- Canadian Centre for Cyber Security issues advisory AV26-552 covering the Progress Kemp LoadMaster vulnerabilities.
- Zero Day Initiative publishes coordinated disclosure advisory ZDI-26-342 assigning CVSS 9.8 and crediting the discoverer.
- watchTowr Labs publishes a detailed technical writeup of the full exploit chain (heap spray, quote-expansion arithmetic, sprintf/system() sink), substantially lowering the bar for independent weaponization.
- eSentire's Threat Response Unit observes exploitation attempts against the /accessv2 endpoint from IPs 192.42.116.58, 192.42.116.105, and 146.70.139.154; attempts are assessed as unsuccessful with no post-compromise activity.
- eSentire publishes a formal security advisory documenting the CVE-2026-8037 exploitation attempts, the three attacker source IPs, and confirming attempts failed with no post-compromise activity.
- Cyber Security News, GBHackers, The Hacker News, and other outlets publish coverage warning of imminent broader exploitation given the public writeup.
- H-ISAC issues a TLP:WHITE threat bulletin on the observed CVE-2026-8037 exploitation attempts, alongside eSentire's public advisory disclosure.
- NVD updates the CVE-2026-8037 record (last modified 2026-07-01T05:16:25Z) to reflect ongoing analysis as active-exploitation reporting accumulates.
- The Hacker News publishes follow-up coverage reiterating active-exploitation-attempt status and urging patch application.
- The Shadowserver Foundation's honeypot network first flags exploitation activity matching CVE-2026-8037, independently corroborating eSentire's earlier observations.
- NVD record for CVE-2026-8037 last modified to refine CPE/affected-product scoping, adding ECS Connections Manager, Object Scale Connection Manager, and MOVEit WAF as products sharing the vulnerable LoadMaster API codepath.
- Shadowserver logs 14 honeypot connections consistent with CVE-2026-8037 exploitation attempts, assessed at 70% confidence as genuine in-the-wild activity rather than benign scanning.
- CISA adds CVE-2026-8037 to its Known Exploited Vulnerabilities catalog (Security Affairs reported the addition as occurring August 5, 2026).
- Deadline set by CISA under Binding Operational Directive 26-04 for U.S. federal agencies to remediate CVE-2026-8037.
Update history for TL-2026-1045
- 2026-08-08 — CVE-2026-8037: CISA Adds Progress Kemp LoadMaster Pre-Auth Command Injection RCE to KEV Catalog: What changed No change to core severity/exploitability/status — already CRITICAL/ACTIVE/9.8 in the existing record. CISA formally added CVE-2026-8037 to its KEV catalog (2026-08-07) with a federal remediation deadline of 2026-08-10 under BO
- 2026-07-19 — CVE-2026-8037: Progress Kemp LoadMaster Uninitialized Heap Leads to Pre-Auth Root RCE: What changed No severity/exploitability/status escalation — remains CRITICAL/ACTIVE/ACTIVE at CVSS 9.8, consistent with the existing record. The update is scope-expansion: three additional Progress products (ECS Connections Manager, Object
- 2026-07-11 — CVE-2026-8037: Pre-Auth RCE in Progress Kemp LoadMaster via /accessv2 Command Injection (escape_quotes() Uninitialized Heap Buffer): What changed No escalation to severity, exploitability, CVSS, or status — all remain CRITICAL/ACTIVE/9.8/ACTIVE, matching the existing record. New indicators (3) Added the CVE-2026-33691 WAF-bypass technique (multi-value Content-Type header
Sources cited for CVE-2026-8037
- The Hacker News: Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth
- The Hacker News: Latest Progress Kemp LoadMaster Pre-Auth RCE coverage
- watchTowr Labs: Enterprise Tech In, Shell Out (Progress Kemp LoadMaster Uninitialized Heap to Pre-Auth RCE CVE-2026-8037)
- Zero Day Initiative Advisory ZDI-26-342
- Progress LoadMaster Vulnerabilities Documentation
- Cyber Security News: Critical Progress Kemp LoadMaster Vulnerability Enables Pre-Auth Remote Code Execution
- GBHackers: Critical Progress Kemp LoadMaster Vulnerability Enables Pre-Auth Remote Code Execution
- CVEFeed: CVE-2026-8037 - OS Command Injection Remote Code Execution Vulnerability
- SecurityOnline: Progress Kemp LoadMaster Alert - Multiple RCE and WAF Bypass Flaws Patched
- GuardianMSSP: Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth
- teamwin: Critical Progress Kemp LoadMaster Vulnerability Enables Pre-Auth Remote Code Execution
- NVD: CVE-2026-8037 Detail
Detection coverage for TL-2026-1045
As of 2026-08-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1045 across Splunk SPL, Microsoft KQL and Sigma, covering 33 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.