wazuh
Security Productsoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting wazuh.
- CVE-2026-67307Wazuh before 5.0.0-beta3 Cluster Attribution Spoofing via Inventory Sync6.3
- CVE-2026-67308Wazuh GitHub Actions Shell Injection via Fork Pull Request10.0
- CVE-2026-28220Wazuh cluster DAPI arbitrary callable deserialization and RBAC context injection allow a cluster peer to execute privileged functions on the master node8.4
- CVE-2026-44251Wazuh : size_t underflow in msgs.c ReadSecMSG causes wazuh-remoted DoS and potential heap overflow via crafted agent message6.5
- CVE-2026-40106Wazuh: Heap-based Buffer Overflow in syscheck Registry Wildcard Expansion (LPE / DoS)4.7
- CVE-2026-39359Wazuh: Unauthenticated Path Traversal in authd via Agent Group Name7.5
- CVE-2026-34150Wazuh: Heap buffer overflow in wazuh-analysisd via rootcheck event parsing7.5
- CVE-2026-33754Wazuh: Unauthenticated cluster packet length leads to uncontrolled memory allocation (remote DoS)6.5
- CVE-2026-33434Wazuh: Rate Limit Bypass via /events Endpoint4.3
- CVE-2026-41499Wazuh: Multiple Heap-based NULL WRITE Buffer Underflows in parse_uname_string()6.5
- CVE-2026-30893Wazuh cluster sync path traversal in decompress_files() enables arbitrary file write and code execution from authenticated cluster peer9.0
- CVE-2026-28221Wazuh: Pre-auth stack-based buffer overflow in wazuh-remoted print_hex_string() due to signed char promotion on x86_646.5
- CVE-2026-26206Wazuh: API brute-force protection bypass via race condition in login attempt tracking6.5
- CVE-2026-26204Wazuh: Heap-based NULL WRITE Buffer Underflow in GetAlertData4.4
- CVE-2025-15612Wazuh Provisioning Scripts / Build Infrastructure Improper Certificate Validation leading to MITM and RCE4.8