PT-2026-46231 · Progress · Progress Adc+1

·

CVE-2026-8037

·

Published

2026-06-04

·

Updated

2026-07-21

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Progress Kemp LoadMaster versions prior to 7.2.63.2 Progress Kemp LoadMaster LTSF versions prior to 7.2.54.17 Progress ADC Products (affected versions not specified) Progress ECS Connection Manager (affected versions not specified) Progress Object Scale Connection Manager (affected versions not specified) Progress MOVEit WAF (affected versions not specified)
Description An unauthenticated remote code execution flaw exists in the API component of Progress ADC products, including Kemp LoadMaster. The issue stems from a two-bug chain in the escape quotes() function within the /accessv2 endpoint. Specifically, the function uses malloc() instead of calloc(), resulting in uninitialized heap memory, and fails to append a null terminator to the escaped output. By sending a specially crafted request to the /accessv2 endpoint using the apiuser parameter, an attacker can perform heap-grooming to overwrite memory and inject arbitrary shell commands into a system() call, leading to full system compromise as root. Real-world incidents involving active exploitation attempts have been observed.
Recommendations Update Progress Kemp LoadMaster to version 7.2.63.2 or later. Update Progress Kemp LoadMaster LTSF to version 7.2.54.17 or later. As a temporary mitigation, restrict access to the /accessv2 API endpoint or disable the API if not required.

Exploit

Fix

LPE

RCE

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8037
ZDI-26-340
ZDI-26-341
ZDI-26-342

Affected Products

Loadmaster
Progress Adc