CVE-2026-71540
- EPSS 0.35%
- Veröffentlicht 24.09.2026 17:49:29
- Zuletzt bearbeitet 30.09.2026 19:38:27
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. From 3.9.0 until 4.14.7, wazuh-clusterd in framework/wazuh/core/cluster/common.py allocates a payload buffer using the size declare...
CVE-2026-61811
- EPSS 0.37%
- Veröffentlicht 24.09.2026 17:48:01
- Zuletzt bearbeitet 30.09.2026 16:44:39
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. From 3.8.0 until 4.14.7, the _getattributes() function in src/os_xml/os_xml.c recursively processes every XML attribute without a d...
CVE-2026-61802
- EPSS 0.4%
- Veröffentlicht 28.08.2026 02:16:21
- Zuletzt bearbeitet 15.09.2026 19:10:57
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.14.0 through 4.14.6, a low-privilege API user can read the cleartext cluster key from a configuration endpoint that f...
CVE-2026-61800
- EPSS 0.59%
- Veröffentlicht 28.08.2026 02:16:21
- Zuletzt bearbeitet 15.09.2026 19:12:34
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.4.0 through 4.14.6, a party holding the cluster key can write, overwrite, or delete arbitrary files under /var/ossec ...
CVE-2026-61783
- EPSS 0.24%
- Veröffentlicht 27.08.2026 23:19:18
- Zuletzt bearbeitet 15.09.2026 19:13:26
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.14.0 through 4.14.6, an authenticated low-privilege user can read the cluster secret from the manager configuration b...
CVE-2026-54084
- EPSS 0.11%
- Veröffentlicht 27.08.2026 23:12:20
- Zuletzt bearbeitet 15.09.2026 19:16:22
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.0.0 through 4.14.6, a malicious or man-in-the-middle enrollment manager can crash a Wazuh agent during enrollment by ...
CVE-2026-54085
- EPSS 0.24%
- Veröffentlicht 27.08.2026 22:55:18
- Zuletzt bearbeitet 15.09.2026 19:14:47
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.2.0 through 4.14.6, multiple active response scripts pass attacker-influenced alert fields to privileged system comma...
CVE-2026-54083
- EPSS 0.33%
- Veröffentlicht 27.08.2026 22:45:37
- Zuletzt bearbeitet 15.09.2026 19:19:39
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. The ip-customblock active response script contains a path traversal vulnerability that lets an attacker create or delete arbitrar...
CVE-2026-49392
- EPSS 0.19%
- Veröffentlicht 19.08.2026 16:22:49
- Zuletzt bearbeitet 15.09.2026 19:23:30
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.6.0 until 4.14.6 and 5.0.0-beta3, DB::getFile() and DB::searchFile() in src/syscheckd/src/db/src/file.cpp concatenate a monitored file path into SQLi...
CVE-2026-44256
- EPSS 0.29%
- Veröffentlicht 19.08.2026 16:21:49
- Zuletzt bearbeitet 18.09.2026 14:52:06
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.4.0 until 4.14.6 and 5.0.0-beta2, api/api/middlewares.py decodes the Basic authentication username before credential validation and passes it to the ...