Skip to content
Threat Feed
high advisory

Progress Autonomous REST Connector GenAI Agents Vulnerability

Progress Software has released a security advisory regarding CVE-2026-91140, a critical vulnerability affecting the ARCGenAI-Generator component in versions prior to 2.1.

CVE search metadata

CVE search record: CVE-2026-91140. Severity: critical. CVSS: 9.6. KEV: no. Product: Autonomous REST Connector GenAI Agents ARCGenAI-Generator (< 2.1). Brief: Progress Autonomous REST Connector GenAI Agents Vulnerability. Brief link: https://feed.craftedsignal.io/briefs/2026-10-progress-arcgenai/

Progress Software has disclosed a critical security vulnerability, identified as CVE-2026-91140, impacting the Autonomous REST Connector GenAI Agents (ARCGenAI-Generator) product. This vulnerability affects all versions of the product prior to 2.1. The flaw was detailed in a security bulletin published in September 2026. Given the nature of the software, which facilitates connectivity for Generative AI agents, this vulnerability could potentially lead to unauthorized access or manipulation of data streams if successfully exploited. Administrators are advised to apply the mandatory updates provided by Progress to secure their deployments against this risk.

Impact

The vulnerability poses a significant risk to organizations integrating ARCGenAI-Generator into their AI infrastructure. Successful exploitation could compromise the integrity and confidentiality of the data being processed or transmitted by the GenAI agents, potentially leading to unauthorized information disclosure or service disruption within the enterprise network.

Recommendation

  • Upgrade Progress Autonomous REST Connector GenAI Agents ARCGenAI-Generator to version 2.1 or later immediately.
  • Review the Progress DataDirect Critical Security Alert Bulletin for specific guidance on CVE-2026-91140.
  • Audit network logs for anomalous traffic patterns originating from or destined for servers hosting the ARCGenAI-Generator component.

Mitigations

Upgrade ARCGenAI-Generator to version 2.1 or later

immediate IT Operations

CVE-2026-91140