Progress Kemp LoadMaster pre-auth flaw under active exploitation
Researchers disclosed a critical flaw in Progress Software's Kemp LoadMaster $PRGS that lets an unauthenticated attacker run system commands on the load balancer with no login. Because these appliances sit at the network edge, one hit opens a direct path inside. Exploitation atte
A critical vulnerability in the widely used Progress Kemp LoadMaster $PRGS lets an unauthenticated attacker send crafted input to the appliance's API and run system commands with root privileges, no login required. The bug stems from a sanitizing function that fails to properly terminate a cleaned string, spilling into adjacent memory. Only appliances with the API enabled are affected, and Progress has released patched versions. Security firm eSentire says exploitation attempts began June 29, though the early attempts it observed failed. A working proof-of-concept exploit is already public, and past edge-appliance flaws of this kind were folded into ransomware operations within days. Load balancers sit at the very edge of a corporate network, so a single foothold there gives an attacker an unobstructed route deeper inside. Patching fast and confirming whether the API is exposed is the practical priority.