ZeroHour

Vulnerabilities

262 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-2041
+2 in the same advisory: …2043 …2042
Authenticated Command Injection RCE in Nagios XI Zabbix Agent Config Wizard

CVE-2026-2041 is a command injection flaw (CWE-78) in the zabbixagent_configwizard_func method of Nagios XI (listed in the advisory under the vendor name 'Nagios Host'), allowing remote authenticated attackers to execute arbitrary code. It is triggered when a user-supplied string passed to the Zabbix Agent configuration wizard function is not properly validated before being used in a system call. An attacker with valid credentials can run code in the context of the service account, giving them control of the monitoring server at that account's privileges. Any organization running an affected Nagios XI installation is exposed, though exploitation requires a low-privilege authenticated account and access to the configuration wizard. No public PoC or confirmed in-the-wild exploitation is known yet, but the very high EPSS score (73.4% within 30 days, 99th percentile) suggests exploitation attempts are likely soon.

Do: Update Nagios XI to the patched release identified in the vendor advisory once available, and in the meantime restrict which accounts can reach the configuration wizards. Place exposed Nagios XI servers behind a VPN or IP allowlist, enforce MFA on the web UI, and audit logs for unexpected system command activity originating from config wizard requests. Given the high EPSS score, prioritize patching and monitor for exploitation activity.

8.873%
  • nagios xi
moderateLow thousands of internet-exposed Nagios XI servers (public scans); total deployments likely in the tens of thousands, mostly on internal networks
CVE-2025-67255
+1 in the same advisory: …67254
In NagiosXI 2026R1.0.1 build 1762361101, Dashboard parameters lack proper filtering, allowing any authenticated user to exploit a SQL Injection vulnerability.

In NagiosXI 2026R1.0.1 build 1762361101, Dashboard parameters lack proper filtering, allowing any authenticated user to exploit a SQL Injection vulnerability.

NVD description · AI analysis pending
8.8
group max
1%
  • nagios nagios xi
CVE-2025-34288
Nagios XI versions prior to 2026R1.1 are vulnerable to local privilege escalation due to an unsafe interaction between sudo permissions and application file per

Nagios XI versions prior to 2026R1.1 are vulnerable to local privilege escalation due to an unsafe interaction between sudo permissions and application file permissions. A user‑accessible maintenance script may be executed as root via sudo and includes an application file that is writable by a lower‑privileged user. A local attacker with access to the application account can modify this file to introduce malicious code, which is then executed with elevated privileges when the script is run. Successful exploitation results in arbitrary code execution as the root user.

NVD description · AI analysis pending
8.62%
  • nagios nagios xi
CVE-2025-34322
+1 in the same advisory: …34323
Nagios Log Server versions prior to 2026R1.0.1 contain an authenticated command injection vulnerability in the experimental 'Natural Language Queries' feature.

Nagios Log Server versions prior to 2026R1.0.1 contain an authenticated command injection vulnerability in the experimental 'Natural Language Queries' feature. When this feature is configured, certain user-controlled settings—including model selection and connection parameters—are read from the global configuration and concatenated into a shell command that is executed via shell_exec() without proper input handling or command-line argument sanitation. An authenticated user with access to the 'Global Settings' page can supply crafted values in these fields to inject additional shell commands, resulting in arbitrary command execution as the 'www-data' user and compromise of the Log Server host.

NVD description · AI analysis pending
8.6
group max
9%
  • nagios log server
CVE-2024-13997
+2 in the same advisory: …13998 …47698
Nagios XI versions prior to 2024R1.1.3 contain a privilege escalation vulnerability in which an authenticated administrator could leverage the Migrate Server fe

Nagios XI versions prior to 2024R1.1.3 contain a privilege escalation vulnerability in which an authenticated administrator could leverage the Migrate Server feature to obtain root privileges on the underlying XI host. By abusing the migration workflow, an admin-level attacker could execute actions outside the intended security scope of the application, resulting in full control of the operating system.

NVD description · AI analysis pending
9.4
group max
1%
  • nagios nagios xi
CVE-2024-13992
Nagios XI versions prior to < 2024R1.1 is vulnerable to a cross-site scripting (XSS) when a user visits the "missing page" (404) page after following a link fro

Nagios XI versions prior to < 2024R1.1 is vulnerable to a cross-site scripting (XSS) when a user visits the "missing page" (404) page after following a link from another website. The vulnerable component, page-missing.php, fails to properly validate or escape user-supplied input, allowing an attacker to craft a malicious link that, when visited by a victim, executes arbitrary JavaScript in the victim’s browser within the Nagios XI domain.

NVD description · AI analysis pending
5.1<1%
  • nagios nagios xi
CVE-2025-34277
Nagios Log Server versions prior to 2024R1.3.1 contain a code injection vulnerability where malformed dashboard ID values are not properly validated before bein

Nagios Log Server versions prior to 2024R1.3.1 contain a code injection vulnerability where malformed dashboard ID values are not properly validated before being forwarded to an internal API. An attacker able to supply crafted dashboard ID values can cause the system to execute attacker-controlled data, leading to arbitrary code execution in the context of the Log Server process.

NVD description · AI analysis pending
9.4
group max
2%
  • nagios log server
CVE-2025-34284
Nagios XI versions prior to 2024R2 contain a command injection vulnerability in the WinRM plugin.

Nagios XI versions prior to 2024R2 contain a command injection vulnerability in the WinRM plugin. Insufficient validation of user-supplied parameters allows an authenticated administrator to inject shell metacharacters that are incorporated into backend command invocations. Successful exploitation enables arbitrary command execution with the privileges of the Nagios XI web application user and can be leveraged to modify configuration, exfiltrate data, disrupt monitoring operations, or execute commands on the underlying host operating system.

NVD description · AI analysis pending
9.4
group max
4%
  • nagios nagios xi
CVE-2025-34280
+2 in the same advisory: …34278 …7319
Nagios Network Analyzer versions prior to 2024R2.0.1 contain a vulnerability in the LDAP certificate management functionality whereby the certificate removal op

Nagios Network Analyzer versions prior to 2024R2.0.1 contain a vulnerability in the LDAP certificate management functionality whereby the certificate removal operation fails to apply adequate input sanitation. An authenticated administrator can trigger command execution on the underlying host in the context of the web application service, resulting in remote code execution with the service's privileges.

NVD description · AI analysis pending
8.6
group max
1%
  • nagios network analyzer