CVE-2017-15524: Kemptechnologies Web Application Firewall

Critical severity, CVSS 9.1. EPSS: 1.2% chance of exploitation in the next 30 days.

The Application Firewall Pack (AFP, aka Web Application Firewall) component on Kemp Load Balancer devices with software before 7.2.40.1 allows a Security Feature Bypass via an HTTP POST request.

Affected products

Published 2017-12-19. Last modified 2026-06-17.