logo

Critical 9.1 CVSS Flaws Threaten Total Wazuh Cluster Takeover

ID: 8e200740-5586-5907-af64-ecac3cc877cb

STIX ID: report--8e200740-5586-5907-af64-ecac3cc877cb

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-03-24

Date Updated: 2026-04-23

Author: Ddos

...
...

Two critical vulnerabilities in the Wazuh cluster (CVE-2026-25769 insecure deserialization and CVE-2026-25770 insecure file-write/chroot) can allow an attacker to achieve full cluster compromise and root-level privilege escalation; administrators should upgrade to Wazuh 4.14.3 and harden ossec.conf permissions and cluster write paths immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.