<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:progress:autonomous_rest_connector_genai_agents_arcgenai_generator:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aprogressautonomous_rest_connector_genai_agents_arcgenai_generator/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 07 Oct 2026 04:37:25 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aprogressautonomous_rest_connector_genai_agents_arcgenai_generator/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Progress Autonomous REST Connector GenAI Agents Vulnerability</title><link>https://feed.craftedsignal.io/briefs/2026-10-progress-arcgenai/</link><pubDate>Wed, 07 Oct 2026 04:37:25 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-progress-arcgenai/</guid><description>Progress Software has released a security advisory regarding CVE-2026-91140, a critical vulnerability affecting the ARCGenAI-Generator component in versions prior to 2.1.</description><content:encoded><![CDATA[<p>Progress Software has disclosed a critical security vulnerability, identified as CVE-2026-91140, impacting the Autonomous REST Connector GenAI Agents (ARCGenAI-Generator) product. This vulnerability affects all versions of the product prior to 2.1. The flaw was detailed in a security bulletin published in September 2026. Given the nature of the software, which facilitates connectivity for Generative AI agents, this vulnerability could potentially lead to unauthorized access or manipulation of data streams if successfully exploited. Administrators are advised to apply the mandatory updates provided by Progress to secure their deployments against this risk.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability poses a significant risk to organizations integrating ARCGenAI-Generator into their AI infrastructure. Successful exploitation could compromise the integrity and confidentiality of the data being processed or transmitted by the GenAI agents, potentially leading to unauthorized information disclosure or service disruption within the enterprise network.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade Progress Autonomous REST Connector GenAI Agents ARCGenAI-Generator to version 2.1 or later immediately.</li>
<li>Review the Progress DataDirect Critical Security Alert Bulletin for specific guidance on CVE-2026-91140.</li>
<li>Audit network logs for anomalous traffic patterns originating from or destined for servers hosting the ARCGenAI-Generator component.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>cve-2026-91140</category><category>supply-chain</category></item></channel></rss>