Nagios vulnerabilities
6 CVEs tracked
In the reporting period, the Nagios monitoring platform surfaced with multiple critical vulnerabilities (CVE-2026-48550 through CVE-2026-48554). Key themes include authenticated remote code execution (RCE) and client-side attacks (XSS, CSRF bypass). Specifically, CVE-2026-48554 allows RCE via macro substitution and CVE-2026-48553 via NRDP. Defenders should immediately update Nagios Core to 4.5.14 and XI to 2026R1.7, and review sudoers configurations for the related Linuxfabrik plugin vulnerability (CVE-2026-52817).
Azərbaycanca: Hesabat dövründə Nagios monitorinq platforması çoxsaylı kritik boşluqlarla (CVE-2026-48550 - CVE-2026-48554) üzə çıxıb. Əsas mövzular autentifikasiya olunmuş uzaqdan kod icrası (RCE) və müştəri tərəfində hücumlardır (XSS, CSRF bypass). Xüsusilə, CVE-2026-48554 makro əvəzetmə, CVE-2026-48553 isə NRDP vasitəsilə RCE-yə imkan verir. Müdafiəçilər dərhal Nagios Core (4.5.14) və XI (2026R1.7) versiyalarına yeniləməli, həmçinin əlaqəli Linuxfabrik plugin zəifliyinə (CVE-2026-52817) görə sudoers konfiqurasiyasını nəzərdən keçirməlidir.
This vendor's CVEs6
This hub is built from skopnix's own reporting on Nagios: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.