The Desk · The Wire · Hacked Today? · Data Center RSS
The Perimeter Site

Progress LoadMaster Remote Code Execution Lands on CISA Must-Patch List

Ingrid Solheim
2026-08-10
# Progress LoadMaster Remote Code Execution Lands on CISA Must-Patch List The Technology sector has spent the last seven days firmly entrenched as the primary target for attackers, ranking first out of 17 sectors with just over 400 stories recorded. With 82 new incidents hitting the wire today alone, the sheer volume is enough to make any compliance officer reach for the gin. But if you look past the raw numbers and the breathless press releases from "security partners," a more tedious and worrying pattern emerges. We aren't just seeing a spike in vulnerabilities; we're seeing a concentrated assault on the management layer. I am talking about the tools that administrators use to manage everything else: load balancers, remote monitoring and management (RMM) software, and business intelligence platforms. These are the "god-mode" tools of the enterprise. When they break, they don't just leak a few emails; they hand over the keys to the entire estate. Take the Progress LoadMaster situation. CISA has stepped in with an urgent directive for federal agencies to patch a critical remote code execution vulnerability. For those who spend more time reading policy than packet captures, a load balancer is essentially the traffic cop of the network. If the cop is compromised, the attacker doesn't have to pick a lock; they can simply redirect all the traffic into their own pockets. The official line from these vendors usually follows a predictable script: "We are committed to the security of our customers." This is a delightful phrase that means absolutely nothing in a court of law or a regulatory hearing. What matters is the window between the zero-day exploit appearing in the wild and the moment the patch is actually applied across a distributed fleet. In the case of Progress, we're seeing the gap where attackers are already active while the paperwork for the "emergency" update is still being routed through procurement chains. Then there is Storm-1175. Microsoft has warned that this China-linked group is turning N-able's N-central RMM tool into a ransomware launchpad. An RMM tool is, by design, intended to have deep, unfettered access to every endpoint it manages. It is the ultimate prize for any state-sponsored actor. By exploiting a "god-mode" vulnerability here, Storm-1175 isn't just attacking one company; they are hijacking the very mechanism used to keep companies secure. This is where the second-order effect becomes truly nasty. The obvious victims are the firms running N-central. But the real carnage happens two steps downstream at the Managed Service Providers (MSPs). If an MSP's RMM tool is compromised, every single one of their clients is effectively breached by proxy. The client might have the most expensive firewall money can buy, but it doesn't matter when the attacker arrives via a trusted administrative channel that has already been granted full permissions. It is a systemic failure masquerading as a software bug. I've seen this movie before. It rhymes with the SolarWinds debacle of 2020, though the scale differs. SolarWinds was a slow-burn espionage operation; the current trend toward using RMMs for rapid ransomware deployment is far more visceral. The difference here is speed. Attackers are no longer interested in sitting quietly in a network for six months; they want to encrypt the disks before the CISO has finished their morning coffee. Of course, the industry's response is always to call for "better hygiene" or "zero trust." I find this tiresome. Zero trust is a wonderful architectural goal, but it's practically impossible to implement when you're relying on third-party tools that require absolute privilege to function. You cannot have a "least privilege" model if the tool you bought specifically to manage your servers requires "Domain Admin" rights just to install an update. Then we have Metabase. They've just patched a critical SQL injection vulnerability that was exploited as a zero-day. This allowed attackers to gain administrative access and steal data. While a business intelligence tool seems less critical than a load balancer, it's often where the most sensitive aggregated data lives. It is the "crown jewel" repository. From a regulatory perspective, this is where things get interesting, and frustratingly slow. In Brussels, the GDPR's 72-hour notification window remains the gold standard for pressure, though in practice, it often results in a flurry of vague notices that tell you your data *might* have been accessed, usually sent three days before the weekend. In Oslo, we see similar tensions between disclosure requirements and the desire to keep a breach quiet until the "remediation" is complete. The reality is that most of these regulations are toothless against supply chain collapses. When a tool like N-able or Progress fails, the resulting data breach isn't a failure of the victim's policy; it's a failure of the vendor's secure development lifecycle. Yet, the fines almost always land on the entity that was breached, not the vendor who shipped the vulnerability. The law requires the data controller to protect the data, regardless of whether the tool they were told to use was fundamentally flawed. Some will argue that this is simply the cost of doing business in a complex ecosystem and that patching is the only viable defence. I disagree. Patching is a reactive treadmill. If you are relying on a vendor's ability to find a bug before a nation-state actor does, you aren't managing risk; you're gambling. The real question we should be asking is why we continue to permit "god-mode" tools to operate with such concentrated authority across entire sectors. We have built a digital infrastructure where a single vulnerability in one load balancer or one RMM server can trigger a cascading failure across hundreds of organisations simultaneously. We are pricing in the risk of an individual server failing, but we aren't pricing in the risk of the management layer evaporating. Until regulators start demanding architectural proof of isolation, rather than just a signed piece of paper saying a vendor follows "industry standards", we will keep seeing these spikes. I suspect the next few months will bring more of this. Once Storm-1175 proves that RMM tools are an efficient vector for ransomware, every other group on the wire will be looking for their own entry point into the management stack. Whether the vendors can move faster than the attackers is a lovely thought, but history suggests otherwise. I'll be keeping an eye on who files their breach notices by Tuesday and which "critical" patches are actually being deployed instead of just downloaded to a folder called 'Updates_Pending'.
◼
← More from the Desk Live Wire →

Tracking a CVE from this story? Hazard shows which vulnerabilities are confirmed exploited in the wild — and what the resulting breaches have cost UK organisations.

DISCLAIMER: Articles on this site are generated automatically from public security news feeds for educational and informational purposes. They may contain errors, and nothing here constitutes security, legal, or compliance advice. Verify details against original advisories and vendor bulletins before acting on them.