Junglewise Threat Intelligence

CVE-2026-2514: Progress Flowmon ADS cross-site scripting via malicious network data

CVE-2026-2514 · Severity: medium · CVSS 6.1 · Published 2026-03-12

Vendors: Progress.

Executive brief

Flowmon ADS is a network monitoring and analysis platform used to observe and understand network traffic patterns. A vulnerability allows attackers who can send traffic to Flowmon's monitoring ports to inject malicious code that executes in the browser of authenticated users viewing the monitoring interface, potentially leading to unauthorized actions, credential theft, or data exfiltration.

Technical details

This is a stored cross-site scripting (XSS) vulnerability in Flowmon ADS versions prior to 12.5.5 and 13.0.3. An attacker with network access to Flowmon monitoring ports can craft malicious network data payloads that are processed and stored by Flowmon ADS. When an authenticated user views this data in the web interface, the malicious script executes in their browser context. No user interaction beyond normal platform usage is required beyond the initial attack vector of sending crafted packets to the monitoring ports. The vulnerability impacts confidentiality and integrity through potential session hijacking, credential capture, or malicious actions executed on behalf of the user. Patches are available in versions 12.5.5 and 13.0.3 and later.

Affected products

  • Progress Flowmon ADS prior to 12.5.5 and 13.0.3

Timeline

  • 2026-03-12: disclosed

References