Issues Resolved
- Last Updated: January 9, 2026
- LoadMaster
- LoadMaster LTSF
- Documentation
| LM-8336 | Security: Fixed a Command Injection Remote Code Execution (RCE) vulnerability in the delcert Application Programming Interface (API) and User Interface (UI). |
| LM-8334 | Security: Fixed a Command Injection Remote Code Execution (RCE) vulnerability in the getcipherset API and UI. |
| LM-8332 | Security: Fixed a Command Injection Remote Code Execution (RCE) vulnerability in the addapikey API and UI. |
| LM-8331 | Security: Fixed a Command Injection Remote Code Execution (RCE) vulnerability in the listapikeys API and UI. |
| LM-8329 | Security: Fixed a Stored Cross-Site Scripting (XSS) issue in /progs/doconfig/setmotd. |
| LM-8327 | Security: Fixed a Directory Traversal to File Enumeration issue in dodownloadwafauditlog API and UI. |
| LM-8325 | Security: Fixed a Stored Cross-Site Scripting (XSS) issue in /progs/doconfig/setclickthrough. |
| LM-8323 | Security: Fixed a Command Injection Remote Code Execution (RCE) vulnerability in the delapikey API and UI. |
| LM-8022 | Platforms: Added support for AMD processors in public and private clouds that support them. |
| LM-8021 | Kernel: Fixed a null pointer dereference that caused a system crash. |
| LM-7966 | GEO: Fixed an upgrade issue where the cluster check mapping menu and availability anomalies may occur after upgrading from a system where the remote protocol is not specified in the configuration file. |
| LM-7810 | FIPS: Fixed issues where the Add Received Cipher Name and Require SNI hostname flags did not work when enabled in the FIPS UI. |
| LM-7522 | Login: Fixed an issue where users were unable to authenticate to the UI using the alternate UPN suffix. |
| LM-5296 | FIPS: An unwanted string no longer appears on the Generate CSR page while generating a CSR for a non-RSA SSL certificate. |