Mmastodon TechnologyCybersecurity first seen 7 h ago, last 7 h ago, peak #2
Progress Software Patches Critical Command Injection Flaw in DataDirect ARC GenAI Agents
Original: Progress Software Fixes Critical Command Injection Flaw in DataDirect ARC GenAI Agents Progress Software patched a criti
Progress Software has released a patch for a critical command injection vulnerability, tracked as CVE-2026-91140, affecting its DataDirect ARC GenAI Agents. The flaw allowed attackers to execute arbitrary code through malicious OpenAPI input. Security teams are being urged to apply the update promptly, as the vulnerability could expose AI agent deployments to remote code execution attacks.
Why now: A newly patched critical vulnerability in a widely used GenAI product is drawing attention from security professionals tracking remote code execution risks.
Progress SoftwareDataDirect ARC GenAI AgentsCVE-2026-91140
Evidence
- Progress Software Fixes Critical Command Injection Flaw in DataDirect ARC GenAI Agents Progress Software patched a critical command injection vulnerability (CVE-2026-91140) in its DataDirect ARC GenAI Agents that allowed attackers to execute code via malicious OpenAPI… · beyondmachines1@infosec.exchange · 2
API: https://socialmediatrends-api.osmike.com/v1/trends/1471537