In LibreNMS versions 25.12.0 and below a high severity vulnerability CVE-2026-26990 was detected. This vulnerability allows authenticated users to perform time-based blind SQL injection via the `address` parameter in `address-search.inc.php`, enabling attackers to infer database information by manipulating query logic and observing conditional response times. To address this issue, users should upgrade LibreNMS to version 26.2.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-26990.
Read more MonitoringIn LibreNMS versions 25.12.0 and below a medium severity vulnerability CVE-2026-26989 was detected. This vulnerability allows attackers with administrative privileges to perform Stored Cross-Site Scripting (XSS) in the Alert Rules workflow, enabling execution of malicious scripts in the browser of any user who accesses the Alert Rules page. To address this issue, users should upgrade LibreNMS to version 26.2.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-26989.
Read more MonitoringIn changedetection.io versions prior to 0.53.2 a medium severity vulnerability CVE-2026-25527 was detected. This vulnerability allows unauthenticated attackers to read arbitrary local application files via a path traversal flaw in the `/static/<group>/<filename>` route, due to improper validation of the group parameter. To address this issue, users should upgrade changedetection.io to version 0.53.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-25527.
Read more MonitoringIn LibreNMS version 1.46 a high severity vulnerability CVE-2020-36947 was detected. This vulnerability allows authenticated attackers to extract sensitive database information by exploiting a SQL injection flaw in the MAC accounting graph endpoint via the manipulated sort parameter. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2020-36947.
Read more MonitoringIn LibreNMS versions prior to 25.12.0 a medium severity vulnerability CVE-2025-68614 was detected. This vulnerability allows attackers to inject arbitrary HTML or scripts via the Alert Rule API because alert rule names are not properly sanitized, leading to stored cross-site scripting (XSS) when the rules are viewed. To address this issue, users should upgrade LibreNMS to versions 25.12.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-68614.
Read more MonitoringIn Nagios XI versions prior to 2026R1.1 a high severity vulnerability CVE-2025-34288 was detected. This vulnerability allows attackers with local access to escalate privileges to root by abusing a sudo-executed maintenance script that includes a PHP file writable by a lower-privileged user, enabling malicious code injection and resulting in arbitrary code execution with root privileges when the script is run. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-34288.
Read more MonitoringIn Zabbix versions up to and including 7.0.5 and 6.4.15 a medium severity vulnerability CVE-2025-49643 was detected. This vulnerability allows an authenticated user, including the Guest account, to trigger excessive CPU consumption on the web server by supplying specially crafted parameters to the /imgstore.php endpoint. Successful exploitation can lead to a denial-of-service condition, degrading the availability of the Zabbix frontend. To address this issue, users should upgrade Zabbix to versions 7.0.6, 6.4.16 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-49643.
In Zabbix Agent builds for AIX versions up to and including 7.0.5 and 6.4.15 a medium severity vulnerability CVE-2025-49642 was detected. This vulnerability allows local users with write access to the /home/cecuser directory to hijack library loading, potentially leading to arbitrary code execution or privilege escalation. To address this issue, users should upgrade Zabbix Agent to versions 7.0.6, 6.4.16 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-49642.
In Zabbix Frontend versions up to and including 7.0.5 and 6.4.15 a medium severity vulnerability CVE-2025-27232 was detected. This vulnerability allows an authenticated Zabbix Super Admin to exploit the oauth.authorize action to read arbitrary files from the webserver, resulting in potential confidentiality loss. To address this issue, users should upgrade Zabbix to versions 7.0.6, 6.4.16 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-27232.
Read more Monitoring