Checkmk
This hub aggregates every CVE we track for Checkmk, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
110
CVEs tracked
1
Critical
40
High
0
In CISA KEV
Severity distribution
MEDIUM62HIGH40LOW7CRITICAL1
Monthly trend
6
2
5
3
1
1
0
1
1
2
4
0
1
0
0
4
3
2
0
1
6
6
0
5
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Checkmk.
- CVE-2026-9549Fix XSS in service discovery active check output4.8
- CVE-2026-8833XSS in urls5.4
- CVE-2026-8078Fix stored XSS in global settings change log4.8
- CVE-2026-7765User Messages widget leaked issuer messages on shared dashboards5.3
- CVE-2026-7186Fix stored XSS in URL dashboard widget via dangerous URI schemes5.4
- CVE-2026-33457Potential livestatus injection in prediction graph page6.3
- CVE-2026-33456Potential livestatus injection in notification test7.6
- CVE-2026-33455Livestatus injection in monitoring quicksearch6.3
- CVE-2025-39666omd: Local privilege escalation when executing omd commands as root7.3
- CVE-2026-3466Cross-site scripting in dashlet title5.4
- CVE-2026-24096Insufficient permission validation on multiple REST API Quick Setup endpoints8.8
- CVE-2026-20915Stored cross-site scripting in Pending Changes sidebar5.4
- CVE-2026-33276XSS in Unified Search via Unescaped Host/Service Names5.4
- CVE-2025-64998Session hijacking via exposed session signing secret in distributed Checkmk setups7.2
- CVE-2026-2859Unauthenticated Host Enumeration via Observable Response Discrepancy on Deploy Agent Endpoint4.3
Product normalization is registry-driven with AI assist and human review. How it works