Our takeCISA added the Progress Kemp LoadMaster command injection (CVE-2024-8190) to KEV: actively exploited. Patch LoadMaster immediately if you run it yourself; most smaller teams use a cloud or MSP version and can ignore this one.Cyber Resilience desk
Sources (1)
- bleeping · bleeping
What this means for you — Security leader:Patch LoadMaster instances to the latest version immediately; CISA added the flaw to KEV confirming active exploitation.
What this means for you — Lean IT orgs:If you run Progress Kemp LoadMaster, update it right away — attackers are already using this critical command injection flaw.
What this means for you — MSP:Check all client LoadMaster appliances for the patched version; the CISA KEV addition confirms in-the-wild exploitation of this critical command injection.
What this means for you — Researcher:Monitor for exploitation of the Progress LoadMaster command injection now that CISA has listed it in KEV.