Progress Software Vulnerabilities and Affected Products
Vulnerabilities associated with Flowmon ADS.
Products
Clear product- Telerik UI for ASP.NET AJAX17 vulnerabilities
- LoadMaster15 vulnerabilities
- MOVEit WAF10 vulnerabilities
- Object Scale Connection Manager10 vulnerabilities
- Flowmon7 vulnerabilities
- MOVEit Automation6 vulnerabilities
- ECS Connection Manager5 vulnerabilities
- ECS Connections Manager5 vulnerabilities
- Sitefinity5 vulnerabilities
- Telerik Reporting5 vulnerabilities
- Telerik UI for WPF5 vulnerabilities
- Flowmon ADS4 vulnerabilities
- Telerik Report Server3 vulnerabilities
- Chef Automate2 vulnerabilities
- Hybrid Data Pipeline2 vulnerabilities
- Telerik Document Processing Libraries2 vulnerabilities
- Telerik UI for WinForms2 vulnerabilities
- Chef Inspec1 vulnerability
- Kendo UI for Angular1 vulnerability
- Kendo UI for jQuery1 vulnerability
- KendoReact1 vulnerability
- MOVEit Transfer1 vulnerability
- Multi Tenant1 vulnerability
- Multi Tenant LoadMaster1 vulnerability
- Progress® Telerik® Document Processing Libraries1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-9272HIGH | Possibility of unintended database operations when querying data related to detected anomalies in Progress Flowmon ADSIn Progress Flowmon ADS versions prior to 12.5.6 and 13.0.5, a vulnerability exists whereby an adversary who is authenticated as a low-privileged user in the Anomaly Detection System (ADS) may send specially crafted requests that could result in unauthorized access to application data and its modification. CWE-89Jul 2, 2026 | CVSS8.7v4.0 | EPSS0.252% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-2514HIGH | Possibility of unintended actions when viewing maliciously crafted network data in Progress Flowmon ADS web applicationIn Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, a vulnerability exists whereby an adversary with access to Flowmon monitoring ports may craft malicious network data that, when processed by Flowmon ADS and viewed by an authenticated user, could result in unintended actions being executed in the user's browser context. CWE-79Mar 12, 2026 | CVSS8.6v4.0 | EPSS0.189% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-2513HIGH | Possibility of unintended actions when an administrator clicks a malicious link in the Progress Flowmon ADS web applicationA vulnerability exists in Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, whereby an administrator who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions within their authenticated web session. CWE-79Mar 12, 2026 | CVSS8.6v4.0 | EPSS0.286% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-13774HIGH | SQL injection leading to privilege escalation in Progress Flowmon ADSA vulnerability exists in Progress Flowmon ADS versions prior to 12.5.4 and 13.0.1 where an SQL injection vulnerability allows authenticated users to execute unintended SQL queries and commands. CWE-89Jan 13, 2026 | CVSS8.8v3.1 | EPSS0.431% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |