CVE-2024-1212Active Exploitation(progress / loadmaster)

LOWCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Prioritize remediation for progress loadmaster systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.

3.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-12-09. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • loadmaster

Threat summary

  • Active exploitation appears in 3 classified signals
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 3 signals
  • General: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-05-02)
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
loadmaster

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-08: 1Mentions · 2026-05-02: 3Active Exploitation · 2026-04-08: 1Active Exploitation · 2026-05-02: 204-0805-02
Signal classification2 categories
Active Exploitation
375.0%
General
125.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-04-081
Active Exploitation1
2026-05-023
Active Exploitation2General1
Full discourse4 posts
  • Team Cymru Research@teamcymru_S2
    Active Exploitation

    🚨 Top 25 CVE Exploitation Attempts - Team Cymru - S2 (Ranked by unique source IPs over 14 days) 1. CVE-2025-0282 · Ivanti Connect Secure 2. CVE-2025-49706 · SharePoint 3. CVE-2020-3452 · Cisco ASA 4. CVE-2025-61884 · Oracle EBS 5. CVE-2024-32113 · Apache OFBiz 6. CVE-2025-53770 · SharePoint 7. CVE-2025-24893 · XWiki 8. CVE-2025-61882 · Oracle EBS 9. CVE-2025-5777 · Citrix NetScaler 10. CVE-2025-34028 · Commvault 11. CVE-2024-57727 · SimpleHelp 12. CVE-2025-20362 · Cisco ASA/FTD 13. CVE-2024-1212 · Kemp LoadMaster 14. CVE-2024-38856 · Apache OFBiz 15. CVE-2022-40684 · Fortinet 16. CVE-2024-9465 · Palo Alto Expedition 17. CVE-2025-11371 · Gladinet CentreStack 18. CVE-2025-58360 · GeoServer 19. CVE-2025-57819 · FreePBX 20. CVE-2025-31324 · SAP NetWeaver 21. CVE-2024-7593 · Ivanti vTM 22. CVE-2025-31125 · Vite Dev Server 23. CVE-2025-64446 · FortiWeb 24. CVE-2024-12987 · DrayTek Vigor 25. CVE-2018-7600 · Drupal

    Post summary

    The tweet enumerates the 25 CVEs that were most frequently targeted in exploitation attempts over a 14‑day period, confirming that these vulnerabilities are being actively used but providing no PoC, exploit code, or patch details.

    070921.2K
    5.5K followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    Vendor. CISA added CVE-2024-1212 to the Known Exploited Vulnerabilities (KEV) catalog on 2024-11-18, signaling observed exploitation in the wild CISA KEV.

    Post summary

    CISA listed CVE-2024-1212 in its KEV catalog, confirming it is being exploited in the wild.

    1000034
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2024-1212. What happened CISA added CVE-2024-1212 to the Known Exploited Vulnerabilities (KEV) catalog on 2024-11-18, signaling observed exploitation in the wild CISA KEV.

    Post summary

    CVE-2024-1212 has been confirmed as being actively exploited in the wild, as indicated by its addition to CISA’s Known Exploited Vulnerabilities catalog.

    1000035
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://research.lyrie.ai/research/active-exploit-cve-2024-1212-kemp-loadmaster #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The text includes a URL hinting at an active exploit for CVE-2024-1212 but provides no explicit details, evidences, or confirmations within the text itself.

    0000024
    152 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSprogressloadmaster---

Explore more