Elastic Stack Under Fire: 7 New Flaws Expose Files & Crash Servers
ID: cd3debda-5ac9-591d-96d6-36c38d6cffd3
STIX ID: report--cd3debda-5ac9-591d-96d6-36c38d6cffd3
Feed Name: securityonline.info
Elastic released security updates addressing seven vulnerabilities across Elasticsearch, Kibana, Packetbeat, and Metricbeat — notably CVE-2026-0532 (Google Gemini connector SSRF and arbitrary file disclosure, CVSS 8.6) and an LZ4-based information disclosure in Elasticsearch (CVSS 8.4). The advisory also fixes multiple DoS flaws in Kibana and buffer/validation issues in Beats; administrators are urged to upgrade to 8.19.10, 9.1.10, or 9.2.4 or apply the recommended mitigations immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
