Progress disclosed two high-severity vulnerabilities in Flowmon that affect versions prior to 12.5.8, with one issue also affecting versions prior to 13.0.6. CVE-2026-3692 is a CWE-78 flaw that allows an authenticated low-privileged user to craft a request during report generation and trigger unintended command execution on the server, creating a path to compromise confidentiality, integrity, and availability without requiring user interaction.
The second issue, CVE-2026-2737, is a CWE-79 web-session attack in the Flowmon web application that can be triggered if an administrator clicks a malicious link supplied by an attacker. Progress said the flaw can cause unintended actions within the administrator’s authenticated session, exposing organizations to account misuse and broader system impact. The vulnerabilities were reported through Progress and documented in the vendor advisory portal, with affected customers urged to move to fixed releases 12.5.8 and 13.0.6 where applicable.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Public disclosure detailed two high-severity Flowmon vulnerabilities: CVE-2026-2737, a malicious-link web-session attack mapped to CWE-79, and CVE-2026-3692, a command execution flaw mapped to CWE-78. Both disclosures identified affected versions and described high potential impact to confidentiality, integrity, and availability.
Progress published a vendor advisory for CVE-2026-3692 on its community advisory portal. The vulnerability affects Flowmon versions prior to 12.5.8 and allows an authenticated low-privileged user to trigger unintended command execution during report generation.
Progress disclosed that vulnerability CVE-2026-2737, affecting Flowmon versions prior to 12.5.8 and 13.0.6, was received by security@progress.com. The flaw can let an attacker trigger unintended actions in an administrator's authenticated web session if the administrator clicks a malicious link.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.