CVE-2026-9272: Progress Flowmon Anomaly Detection System
High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.
In Progress Flowmon ADS versions prior to 12.5.6 and 13.0.5, a vulnerability exists whereby an adversary who is authenticated as a low-privileged user in the Anomaly Detection System (ADS) may send specially crafted requests that could result in unauthorized access to application data and its modification.
Affected products
- Progress Flowmon Anomaly Detection System: from 12.5.0, before 12.5.6 (fixed in 12.5.6); from 13.0.0, before 13.0.5 (fixed in 13.0.5)
Published 2026-07-02. Last modified 2026-07-07.