Progress
Progress Flowmon: vulnerabilities and CVEs
Progress Flowmon has 7 published vulnerabilities, 6 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.
CVEs7
Last 12 months6
Critical1
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8079 | High (8.7) | 0.32% | — | Jul 2, 2026 | In Progress Flowmon versions prior to 12.5.9 and 13.0.11, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the PDF generation process that results in operations being… |
| CVE-2026-3692 | High (8.7) | 0.57% | — | Apr 2, 2026 | In Progress Flowmon versions prior to 12.5.8, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the report generation process that results in unintended commands being… |
| CVE-2026-2737 | High (8.5) | 0.25% | — | Apr 2, 2026 | A vulnerability exists in Progress Flowmon versions prior to 12.5.8 and 13.0.6, whereby an administrator who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions within their… |
| CVE-2025-11906 | Medium (6.7) | 0.14% | — | Oct 30, 2025 | A vulnerability exists in Progress Flowmon versions prior 12.5.6 where certain system configuration files have incorrect file permissions, allowing a user with access to the default flowmon system user account used for… |
| CVE-2025-10240 | High (8.8) | 0.32% | — | Oct 9, 2025 | A vulnerability exists in the Progress Flowmon web application prior to version 12.5.5, whereby a user who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions within their… |
| CVE-2025-10239 | High (7.2) | 0.38% | — | Oct 9, 2025 | In Flowmon versions prior to 12.5.5, a vulnerability has been identified that allows a user with administrator privileges and access to the management interface to execute additional unintended commands within scripts… |
| CVE-2024-2389 | Critical (9.8) | 93% | — | Apr 2, 2024 | In Flowmon versions prior to 11.1.14 and 12.3.5, an operating system command injection vulnerability has been identified. An unauthenticated user can gain entry to the system via the Flowmon management interface,… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.