Database/Control plane, storage & DevOps

Progress Kemp LoadMaster (including Multi-Tenancy edition): A request handler fails to validate its input before
Impact
A request handler fails to validate its input before passing it to a system call, giving an attacker OS command execution on the LoadMaster with no authentication at all. This explicitly affects the Multi-Tenancy edition — the product line built to let multiple tenants share one LoadMaster — so a single unauthenticated request can compromise the appliance underneath every tenant's virtual services on that instance.
Who can reach it
Fully remote and unauthenticated — a crafted request to the vulnerable API endpoint is sufficient, no login required.
What to do
Software upgrade to the fixed LoadMaster/Multi-Tenancy release per Kemp's advisory. Patch immediately given the unauthenticated, maximum-severity nature of this bug; if this instance is shared across tenants, treat any exposure window as a potential full-tenant-boundary breach and audit for signs of compromise, not just apply the patch.
References
Related entries
- Automated Logic WebCTRL 7.0 / WebCTRL Premium Server / Carrier i-Vu building automation server: Unauthenticated fileCVE-2024-8525 · Automated Logic WebCTRL 7.0 / WebCTRL Premium Server / Carrier i-Vu building automation serverCritical
- Arista CloudVision (Zero Touch Provisioning): Zero Touch Provisioning can be abused to obtain admin privilegesCVE-2025-0505 · Arista CloudVision (Zero Touch Provisioning)Critical
- Deep Sea Electronics DSE855 generator communications gateway v1.1.0-v1.1.26 (realtime.cgi): Incorrect access controlCVE-2025-29270 · Deep Sea Electronics DSE855 generator communications gateway v1.1.0-v1.1.26 (realtime.cgi)Critical
- Commvault Command Center: Unauthenticated ZIP upload + path traversalCVE-2025-34028 · Commvault Command CenterCritical
- HPE OneView (unauthenticated remote code execution): Unauthenticated remote code execution on OneView with scope changeCVE-2025-37164 · HPE OneView (unauthenticated remote code execution)Critical
- Ivanti Sentry: OS command injectionCVE-2026-10520 · Ivanti SentryCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.