logo

Maximum severity Flowmon bug has a public exploit, patch now

ID: 22ba24fd-3bed-5c23-a3e8-c77e2164eedd

STIX ID: report--22ba24fd-3bed-5c23-a3e8-c77e2164eedd

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2024-04-24

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Progress Flowmon has a critical 10/10 vulnerability (CVE-2024-2389) allowing unauthenticated remote command execution; public PoC exploit code and demonstrations exist, researchers showed webshell planting and privilege escalation, and several hundred Flowmon instances appear internet-exposed. Progress released patched versions (v12.3.5 and 11.1.14) and urged updates, while vendor advisories reported no confirmed active exploitation but multiple PoCs and warnings were published.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.