ZDI-26-051: Progress Software Kemp LoadMaster delcert Command Injection Remote Code Execution Vulnerability
Published Feb 2, 2026
·Updated
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Progress Software Kemp LoadMaster. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.1. The following CVEs are assigned: CVE-2025-13447.
Affected Software
1 affected component
Progress Software Kemp LoadMaster
Event History
Feb 2, 2026
Advisory Published
via ZDI·06:00 AM
Data Sourced
via ZDI·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-26-051?
The severity of ZDI-26-051 is critical due to its potential for remote code execution.
2
How do I fix ZDI-26-051?
To fix ZDI-26-051, apply the latest security patches provided by Progress Software for Kemp LoadMaster.
3
Who is affected by the ZDI-26-051 vulnerability?
The ZDI-26-051 vulnerability affects installations of Progress Software Kemp LoadMaster.
4
Is authentication required to exploit ZDI-26-051?
Yes, authentication is required to exploit the ZDI-26-051 vulnerability.
5
What type of attack does ZDI-26-051 enable?
ZDI-26-051 enables network-adjacent attackers to execute arbitrary code.