Vulnerabilities in wazuh
73 resultsVexday analysis
Wazuh apresenta 38 vulnerabilidades registradas, com 12 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Apenas 1 está sob exploração ativa (KEV) e 6 são críticas, sugerindo impacto moderado; a fraqueza dominante é CWE-476 (null pointer dereference), típica de falhas de validação que afetam disponibilidade.
CVE-2026-26206MEDIUMWazuh: API brute-force protection bypass via race condition in login attempt trackingEPSS 0.3%CVE-2024-35177HIGHImproper Access Control in wazuh-agentEPSS 0.3%CVE-2025-64483MEDIUMWazuh API – Agent Configuration Has Improper Access Control in Agent Enrollment EndpointEPSS 0.3%CVE-2024-47770MEDIUMAbility to view Agent list with no privilege access in wazuh-dashboardEPSS 0.3%CVE-2023-42463HIGHwazuh-logcollector integer underflow local privilege escalationEPSS 0.2%CVE-2026-67307HIGHWazuh before 5.0.0-beta3 Cluster Attribution Spoofing via Inventory SyncEPSS 0.2%CVE-2025-15612MEDIUMWazuh Provisioning Scripts / Build Infrastructure Improper Certificate Validation leading to MITM and RCEEPSS 0.2%CVE-2026-54084MEDIUMWazuh agent enrollment NULL pointer dereference via malformed manager responseEPSS 0.2%CVE-2026-26204MEDIUMWazuh: Heap-based NULL WRITE Buffer Underflow in GetAlertDataEPSS 0.2%CVE-2025-54866LOWWazuh installation fails to protected authd.pass on WindowsEPSS 0.2%CVE-2026-40106MEDIUMWazuh: Heap-based Buffer Overflow in syscheck Registry Wildcard Expansion (LPE / DoS)EPSS 0.1%CVE-2026-61811MEDIUMWazuh: Unbounded Recursion in os_xml `_getattributes()` Causes analysisd Worker Thread Stack ExhaustionEPSS —CVE-2026-71540HIGHWazuh Manager cluster header parsing allows pre-authentication memory exhaustionEPSS —