ZDI-CAN-30437: ZDI-26-342: Progress Software Kemp LoadMaster apiuser Uninitialized Memory Remote Code Execution Vulnerability
Published Jun 9, 2026
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Progress Software Kemp LoadMaster. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2026-8037.
Affected Software
1 affected component
Progress Software Kemp LoadMaster
Event History
Jun 9, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-30437?
ZDI-CAN-30437 has a CVSS rating of 9.8, indicating a critical severity level.
2
How do I fix ZDI-CAN-30437?
To fix ZDI-CAN-30437, update to the latest version of Progress Software Kemp LoadMaster as provided by the vendor.
3
What types of attacks does ZDI-CAN-30437 allow?
ZDI-CAN-30437 allows remote attackers to execute arbitrary code without the need for authentication.
4
What systems are affected by ZDI-CAN-30437?
ZDI-CAN-30437 affects installations of Progress Software Kemp LoadMaster software.
5
Is authentication required to exploit ZDI-CAN-30437?
No, authentication is not required to exploit ZDI-CAN-30437.