ZDI-26-342: Progress Software Kemp LoadMaster apiuser Uninitialized Memory Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Progress Software Kemp LoadMaster. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2026-8037.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-342?
ZDI-26-342 has a CVSS rating of 9.8, indicating a critical severity level.
How do I fix ZDI-26-342?
To mitigate ZDI-26-342, you should update Progress Software Kemp LoadMaster to the latest security patch provided by the vendor.
What systems are affected by ZDI-26-342?
ZDI-26-342 affects installations of Progress Software Kemp LoadMaster software.
Is authentication required to exploit ZDI-26-342?
No, authentication is not required to exploit ZDI-26-342, making it particularly dangerous.
What type of vulnerability is ZDI-26-342?
ZDI-26-342 is classified as a remote code execution vulnerability due to uninitialized memory.