CISA warns that attackers are actively exploiting a critical-severity command injection vulnerability in Progress Kemp LoadMaster devices, and it urges organizations to patch immediately. The issue allows an attacker to execute arbitrary commands on vulnerable systems.
SecurityWeek and Bleeping Computer both report that the vulnerability is being targeted in the wild. They cite CISA’s advisory, which emphasizes that the flaw can be exploited remotely without authentication. While the outlets focus on the urgent nature of the threat, they do not present conflicting details about the vulnerability’s severity, affected exposure (remote), or the attacker capability (command execution). Instead, they align on the key message: affected LoadMaster instances should be updated as soon as possible to reduce the risk of compromise.
The reporting centers on CISA’s public guidance rather than new investigative findings from the individual outlets, reflecting a shared reliance on the agency’s assessment of exploitation and urgency for remediation.