Critical Kemp LoadMaster Vulnerability Enables Pre-Auth Root via API

Colleagues, I’d like to flag an important cybersecurity update.
Progress Kemp LoadMaster is affected by a critical vulnerability, CVE-2026-8037. It allows an unauthenticated attacker to execute commands with root privileges via the API.
The risk is especially severe when the API is enabled, as the attack requires no login.
GA v7.2.63.1 and earlier, as well as LTSF v7.2.54.17 and earlier, are affected.
A patch is already available, and I would strongly recommend updating without delay.
Why this matters: LoadMaster often sits at the network edge, so pre-auth flaws like this can quickly become full compromise risks.
Do you really need the API exposed on such devices?#cybersecurity #vulnerability #patchmanagement #apisecurity

