Technology newsroom
CISA Issues Urgent Alert! π¨ Critical Vulnerability in Progress LoadMaster Under Active Exploitation, Administrators Advised to Patch Immediately
CISA has issued an urgent alert advising system administrators to immediately update Progress LoadMaster patches after a critical remote code execution vulnerability, which allows unauthenticated remote code execution, was found to be actively exploited.
π Key Takeaways:
- CISA has added a vulnerability in Progress LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog after confirming active exploitation.
- The vulnerability is rated Critical, allowing malicious actors to execute remote code without authentication.
- System administrators using LoadMaster should update security patches urgently to prevent potential damage.
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert to system administrators worldwide, urging them to immediately update security patches for Progress LoadMaster devices. This follows the detection that a critical severity vulnerability is currently being exploited by malicious actors.
π¨ Vulnerability Details and Risks
The discovered vulnerability in LoadMaster, an Application Delivery Controller (ADC) device also known as a Load Balancer, is extremely dangerous. It allows a remote attacker to successfully execute arbitrary malicious commands on the device without any authentication, enabling hackers to easily gain control of the system.
π‘οΈ CISA's Response and Recommendations
Due to its severity and active exploitation, CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, a list of vulnerabilities that require the most urgent remediation. CISA has urged U.S. federal agencies and organizations worldwide using Progress LoadMaster to immediately verify and install the latest patches from Progress Software. This is crucial to close attack vectors and prevent potential damage to organizational data and network systems.
π¬ Does your organization use Progress Load Balancers? Have you checked and updated them yet?