[CIVN-2026-0405] Multiple Vulnerabilities in Progress Kemp LoadMaster

By Published On: August 12, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple Vulnerabilities in Progress Kemp LoadMaster


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: CRITICAL


Software Affected


Progress Kemp LoadMaster version GA v7.2.63.1 and older

Progress Kemp LoadMaster version LTSF v7.2.54.17 and older

Overview


Multiple vulnerabilities have been reported in Progress Kemp LoadMaster that could allow an unauthenticated attacker to execute arbitrary commands or bypass file upload security controls on the targeted system.


Target Audience:

All organizations and individuals using affected versions of Progress Kemp LoadMaster.


Risk Assessment:

High risk of remote code execution, unauthorized access and security control bypass.


Impact Assessment:

Potential for arbitrary command execution and bypass of security controls.


Description


Progress Kemp LoadMaster is an application delivery controller and load balancing platform used to manage and distribute network traffic across applications and services.


Multiple vulnerabilities have been reported in Progress Kemp LoadMaster due to improper neutralization of special elements used in commands and improper validation of filenames during file upload processing.


Successful exploitation of these vulnerabilities could allow an unauthenticated attacker to execute arbitrary commands or bypass file upload security controls on the targeted system.


Solution


Apply appropriate updates as mentioned by the Vendor:

https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691



Vendor Information


Progress Kemp LoadMaster

https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691


References


 

https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691


CVE Name

CVE-2026-8037

CVE-2026-33691




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmp8fqYACgkQ3jCgcSdc

ys9REw//b3MWrAtuU/B5TlBurxYwFbsWP05QT+31+sapBYe04hQzPG8Evd+1kq1d

MKyFBPS6jEf+xP4o56l0R6Vm8+oLxvdE/V0DW3Ptrs00j29GQVD2NzHkNqyOr9Yp

rN/Jl1F0PLuJ2geDPOyGSqMWok6jHiWDLkYwpcx+x4ZHE/my8DKm9ez5hZJfVdTf

i99hkn1F5t1X2YFtKNCbUKS7mBavKi6hwCK8Jm5D+UZf+vByxdZBd67Fpn2E0bBy

yHU+oYzn/UaPDBEQYNSOGb/s8o+aUUpSbYY/xKzXgrtv7z16cqkDnk+yoK7hdLWx

nKfaPbkNjOvmYndOVCiwATJEfM752ubA2VC5jBAlYsi+TLKffpDPszNfLGurtv0m

wvE31z5yq6RkiQKU6j+XzGi1sBHq5h6G2stfKqkLmbuoIwZWH8oZEWvDdg2pSwbN

YA+ICGF2hMutQrL/0APiKQldFf8HcmrFOjgFxnASkoVWunMp96a5NDZ8gWheKhEk

3/hruNlefHPcCCf3n6WnAijobmhmAdYV1TpRGHNZXqut7NYa85g6fU+mAe2tlaPw

VDQOvRImmoPFkUFEG3Fga4g61VsveB6qANqcK8yWJfbSUWtf+3XcrcHIivAuByZh

U+vdfA0O2rFX9rREXjvN9FXdS6bD9KUNuc02ZrFPHUck9GUFAMk=

=EI9B

—–END PGP SIGNATURE—–

Share this article