ZDI-26-341: Progress Software Kemp LoadMaster dolistapikeys Uninitialized Memory Remote Code Execution Vulnerability
Published Jun 9, 2026
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Progress Software Kemp LoadMaster. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-8037.
Affected Software
1 affected component
Progress Software Kemp LoadMaster
Event History
Jun 9, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-26-341?
The severity of ZDI-26-341 is rated at 7.2 on the CVSS scale.
2
How do I fix ZDI-26-341?
To fix ZDI-26-341, ensure that you apply the latest security patches provided by Progress Software for the Kemp LoadMaster.
3
What type of vulnerability is ZDI-26-341?
ZDI-26-341 is a remote code execution vulnerability caused by uninitialized memory in Progress Software Kemp LoadMaster.
4
Is authentication required to exploit ZDI-26-341?
Yes, authentication is required to exploit the ZDI-26-341 vulnerability.
5
What software versions are affected by ZDI-26-341?
ZDI-26-341 affects installations of Progress Software Kemp LoadMaster.