Tech.Yahoo Critical Vulnerability in Progress DataDirect ARCGenAI Agents Disclosed
Article Content
- •CVE-2026-91140 has a CVSS score of 9.6, indicating a critical vulnerability.
- •The vulnerability allows arbitrary command execution on developer machines via unvalidated filenames.
- •Progress Software has released a patch, but no exploitation has been confirmed in the wild.
Progress Software disclosed a critical vulnerability (CVE-2026-91140) in its DataDirect Autonomous REST Connector GenAI Agents on October 6, 2026. The flaw, with a CVSS score of 9.6, allows attackers to execute arbitrary OS commands via crafted OpenAPI or Swagger documents containing shell metacharacters in filenames. This vulnerability is part of a broader trend of supply-chain vulnerabilities where AI agents treat configuration specifications as trusted input. Progress has released a patch in version 2.1 of the agent definitions. No in-the-wild exploitation or public proof-of-concept exists at the time of disclosure. This incident highlights a structural failure in how AI agents process input, similar to previous vulnerabilities documented earlier in 2026. The lack of automated compliance checks and security certification standards exacerbates the risk associated with these vulnerabilities.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track Progress Software and CVE-2025-53773 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What is CVE-2026-91140?
Has this vulnerability been exploited in the wild?
What should I do if I'm using ARCGenAI Agents?
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…