CVE-2024-1212: Progress Kemp LoadMaster OS Command Injection Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2024-11-18. EPSS: 95.4% chance of exploitation in the next 30 days.
Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.
Affected products
- Progress LoadMaster: from 7.2.48.1, before 7.2.48.10 (fixed in 7.2.48.10); from 7.2.54.0, before 7.2.54.8 (fixed in 7.2.54.8); from 7.2.55.0, before 7.2.59.2 (fixed in 7.2.59.2)
Published 2024-02-21. Last modified 2026-07-13.