CVE-2026-3692: Progress Flowmon

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

In Progress Flowmon versions prior to 12.5.8, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the report generation process that results in unintended commands being executed on the server.

Affected products

  • Progress Flowmon: before 12.5.8 (fixed in 12.5.8)

Published 2026-04-02. Last modified 2026-07-06.