logo

Critical Flaws in Cacti Framework Could Let Attackers Execute Malicious Code

ID: aed7e086-1a57-5e5f-82d0-3816569077c9

STIX ID: report--aed7e086-1a57-5e5f-82d0-3816569077c9

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-05-14

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Cacti maintainers released version 1.2.27 (May 13, 2024) addressing a dozen vulnerabilities — including critical RCEs (CVE-2024-25641, CVE-2024-29895), a high-severity SQL injection (CVE-2024-31445), and a file-inclusion issue (CVE-2024-31459) — many of which affect all supported versions; proof-of-concept exploits are available and prior Cacti flaws have been actively exploited to deliver botnet malware, so users are advised to update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.