
CISA Warns of Critical Progress Kemp LoadMaster Vulnerability Actively Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a warning that threat actors are actively exploiting a critical-severity command injection vulnerability in Progress Kemp LoadMaster products. The flaw, tracked as CVE-2024-1212, carries a CVSS score of 9.8 and allows unauthenticated attackers to execute arbitrary system commands with root privileges. CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies to apply patches by a specified deadline. Exploitation of the flaw could lead to full system compromise, including data theft, malware deployment, or lateral movement within networks. Progress Software released security updates to address the issue, urging all users to upgrade immediately.