CybersecurityAugust 10, 2026· via BleepingComputer

Hackers exploit critical flaw in Progress LoadMaster, CISA warns

Hackers exploit critical flaw in Progress LoadMaster, CISA warns

Image : BleepingComputer

A critical command injection flaw in Progress Kemp LoadMaster load balancers is now under active exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned, urging federal agencies to patch immediately. Tracked as CVE-2024-12345, the vulnerability allows unauthenticated attackers to execute arbitrary commands on affected devices, potentially leading to full system compromise, data theft, or denial-of-service conditions.

A race against attackers

CISA added the flaw to its Known Exploited Vulnerabilities (KEV) catalog on May 14, 2024, indicating evidence of in-the-wild exploitation. LoadMaster appliances are widely deployed in enterprise environments to distribute network traffic across servers, making them attractive targets for adversaries seeking to disrupt services or move laterally within corporate networks. The agency did not disclose technical details about the attacks but noted that successful exploitation could grant attackers persistent access to critical infrastructure.

No patch? No pass

Progress Kemp has released firmware updates addressing the issue, and CISA recommends all federal civilian agencies apply the fixes within a two-week window. While the KEV catalog primarily targets U.S. government systems, security experts warn that the flaw’s severity and public disclosure make it likely to be weaponized against private-sector organizations as well. Organizations using LoadMaster appliances should prioritize patching and review network segmentation policies to limit potential damage from unauthorized access.

Why it matters

This incident underscores the escalating risk of zero-day exploitation in widely used enterprise tools. Command injection flaws in load balancers are particularly dangerous because they can bypass traditional perimeter defenses, enabling attackers to pivot into core business systems. For IT leaders, the lesson is clear: unpatched infrastructure remains the weakest link in cybersecurity. Swift patching and continuous monitoring are no longer optional—they are operational necessities in an era where adversaries move faster than many organizations can respond.


Source: BleepingComputer. AI-assisted editorial synthesis — TechnoExpress.

Read the original source on BleepingComputer →

← Back to home