CISA added CVE-2026-8037 to its Known Exploited Vulnerabilities catalogue on Friday, setting a remediation deadline of today — 10 August. The flaw is a command injection vulnerability in Progress Kemp LoadMaster, rated CVSS 9.6, and it lets an unauthenticated attacker run arbitrary commands on the appliance.
Why this matters for Australian businesses
LoadMaster appliances sit directly in front of web applications, distributing traffic and terminating SSL connections. If an attacker compromises one, they can intercept traffic, redirect users, and pivot into backend systems — all without ever touching your servers directly.
The vulnerability sits in a function called escape_quotes() that was supposed to sanitise user input. It didn’t. watchTowr Labs’ analysis confirmed that crafted requests to the /accessv2 endpoint bypass the control entirely. KEVIntel has logged 792 exploitation attempts from 65 IPs across 18 countries — including Australia.
Here’s something we see regularly across our client base: businesses treat network appliances as “set and forget” devices. They’re not. Load balancers, firewalls, and VPN gateways need the same patching discipline as your servers and endpoints. When a security function literally named escape_quotes() turns out to be the attack surface itself, it’s a reminder that vendor-shipped controls aren’t always bulletproof.
What to do right now
If your organisation uses Kemp LoadMaster, apply the latest firmware update immediately. If a third party manages your load balancing, contact them today and ask for written confirmation that CVE-2026-8037 has been patched. Check that the management interface isn’t exposed to the internet — it shouldn’t be.
Not sure whether your infrastructure includes a LoadMaster appliance? Get in touch with our team. We can audit your network perimeter and confirm nothing’s exposed that shouldn’t be.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
