Critical LoadMaster RCE: What Sysadmins Must Do Now
Critical LoadMaster RCE: What Sysadmins Must Do Now
Why LoadMaster Admins Are on High AlertIf your organisation relies on Progress Kemp LoadMaster as a load balancer or application delivery controller (...
Why LoadMaster Admins Are on High Alert
If your organisation relies on Progress Kemp LoadMaster as a load balancer or application delivery controller (ADC), you are facing a security challenge that demands immediate attention. A critical vulnerability, tracked as CVE-2026-8037, allows remote attackers to execute commands with root privileges without any authentication, provided the device's API is enabled. This is the kind of pre-authentication remote code execution (RCE) that security teams dread, especially when it affects components sitting at the very edge of your network.

First observed exploitation attempts date back to late June 2026, and a public proof-of-concept (PoC) is already circulating. While there is no confirmed report of a full compromise yet, the combination of high severity, internet exposure, and available exploit code makes this a race between patching and potential attackers.
Understanding the Technical Flaw
The vulnerability stems from improper handling of sanitised strings that do not terminate with a null character. This can lead to out-of-bounds reads and, under certain conditions, allow an attacker to inject a malicious payload into a shell. In practice, an attacker can send specially crafted requests to the /accessv2 endpoint with a JSON body designed to trigger the command injection. The result? Full control over the appliance with root privileges.
This is particularly dangerous because LoadMaster devices are typically deployed in front of internal applications, corporate portals, and other services published to the internet. A compromised ADC can act as a gateway to your entire internal infrastructure.
Affected Versions and Severity
The following versions are vulnerable if the API is enabled:
- LoadMaster GA: v7.2.63.1 and earlier
- LoadMaster LTSF: v7.2.54.17 and earlier
Fixed versions are already available: GA v7.2.63.2 and LTSF v7.2.54.18. Treat these updates as urgent. Severity scores have been reported between 9.6 and 9.8, but the operational message is clear: this is a critical flaw that must be addressed immediately.
Additional Risk: WAF Bypass Vulnerability
The same security advisory also addresses another issue, CVE-2026-33691, which allows attackers to bypass Web Application Firewall (WAF) checks during file uploads by using whitespace characters in filenames. If you use LoadMaster's WAF features and allow file uploads, you should apply these patches as well to avoid leaving an alternative path open.
Immediate Mitigation Steps
While patching is the ultimate solution, you can take several steps to reduce your exposure right now:
- Check if the API is enabled. If it is not essential, disable it or restrict access to trusted management networks only.
- Apply access controls. If the API must remain operational, limit access to the affected endpoints using ACLs, firewall rules, and network segmentation.
- Monitor logs. Look for unusual activity targeting /accessv2, especially JSON bodies with multiple keys or patterns that suggest command injection attempts.
- Block known malicious IPs. Observed exploit attempts have been traced to specific addresses, including 192.42.116.58, 192.42.116.105, and 146.70.139.154. Blocking these can help, but remember that attackers can easily change sources.
Lessons for Infrastructure Management
This incident underscores an uncomfortable truth: load balancers and ADCs are critical components that deserve the same level of attention as any other server in your environment. They need to be inventoried, monitored, and patched with the same rigour. In many organisations, these devices are overlooked because they are 'just' traffic managers, but their position makes them prime targets.
For companies in Spain, particularly those in Barcelona, Lleida, Tarragona, and Girona, where digital infrastructure is the backbone of business operations, this is a timely reminder to review your security posture. GDPR compliance also requires you to protect personal data, and a compromised ADC could lead to data breaches with legal and financial consequences.
How ALMC.es Can Help
Managing security across multiple servers and devices can be overwhelming, especially for small and medium-sized businesses with limited IT resources. That is where Abuse Shield comes in. Our service centralises the protection of your servers by automatically blocking malicious IPs, managing fail2ban across multiple machines, and sharing a reputation feed among all your servers. This means you can respond to threats like CVE-2026-8037 more effectively, with less manual effort.
Don't wait for an attacker to exploit a known vulnerability. Take action today to secure your perimeter and your entire infrastructure.
Related
- GhostLock CVE-2026-43499: Patch Your Linux Servers Now
- RoguePlanet: Microsoft Patches Defender Zero-Day, Update Now
- NPM Supply Chain Attack: How a Malicious SDK Compromised Crypto Wallets
- Desarrollo web
Put these ideas into practice
Talk to ALMC about a solution for your business. Explore your options or contact our team.
