Security News

Urgent Patch Alert: Actively Exploited Flaw Found in Progress LoadMaster Software

Security Week · 10 Aug 2026
Key Takeaway Ask your IT provider or managed service partner whether they use Progress LoadMaster, and confirm it has been patched immediately if so.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about a critical vulnerability in Progress LoadMaster, a widely used load balancing and application delivery tool. The flaw allows unauthenticated, remote attackers to execute arbitrary commands on affected systems, meaning they don't need a username or password to break in and take control.

CISA has confirmed the vulnerability is being actively exploited in real-world attacks, prompting the agency to call for immediate patching. Software of this type is often used behind the scenes to manage network traffic for business applications, making it an attractive target for attackers looking to gain a foothold inside an organisation's systems without being noticed.

While LoadMaster is more commonly deployed by larger organisations and managed service providers, Australian small businesses that rely on third-party IT providers or web hosting services should check whether this software is part of their infrastructure. Attacks on foundational network tools like this can have flow-on effects for smaller businesses that depend on the same service providers or supply chains.

Summarised by CISO AI from Security Week. We link back to every original so you can read it yourself.