CVE-2026-61550 | Icinga 2 is an open source monitoring system. From 2.8 until 2.14.9, 2.15.4, and 2.16.2, certificate update JSON-RPC message handling does not validate that the sender is a trusted endpoint. An unauthenticated network attacker able to connect to TCP port 5665 can replace the node certificate and trusted CA certificate, impersonate a trusted node, and take control of the node. This issue is fixed in versions 2.14.9, 2.15.4, and 2.16.2.
Icinga 2 is an open source monitoring system. From 2.8 until 2.14.9, 2.15.4, and 2.16.2, certificate update JSON-RPC message handling does not validate that the sender is a trusted endpoint. An unauthenticated network attacker able to connect to TCP port 5665 can replace the node certificate and trusted CA certificate, impersonate a trusted node, and take control of the node. This issue is fixed in versions 2.14.9, 2.15.4, and 2.16.2.
- 🔗 github.com/Icinga/icinga2/security/advisories/GHSA-v…
- 🔗 github.com/Icinga/icinga2/pull/10907
- 🔗 github.com/Icinga/icinga2/commit/4b7fb3405f4616a24b2…
- 🔗 github.com/Icinga/icinga2/commit/6c2e0db3819f859910a…
- 🔗 github.com/Icinga/icinga2/commit/a6f7cc7a4ef8beed023…
- 🔗 github.com/Icinga/icinga2/commit/d37b0cfd7d9595ae2f0…
- 🔗 github.com/Icinga/icinga2/releases/tag/v2.14.9
- 🔗 github.com/Icinga/icinga2/releases/tag/v2.15.4
```Code``` unterstützt. Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-09-05 | 2026-09-22 |
|---|---|---|
| ≥90 % | 0 | 491 |
| ≥50 % | 0 | 1475 |
| ≥10 % | 0 | 0 |
| <10 % | 300 | 0 |
CVE-2026-61550 | Icinga 2 is an open source monitoring system. From 2.8 until 2.14.9, 2.15.4, and 2.16.2, certificate update JSON-RPC message handling does not validate that the sender is a trusted endpoint. An unauthenticated network attacker able to connect to TCP port 5665 can replace the node certificate and trusted CA certificate, impersonate a trusted node, and take control of the node. This issue is fixed in versions 2.14.9, 2.15.4, and 2.16.2.
Icinga 2 is an open source monitoring system. From 2.8 until 2.14.9, 2.15.4, and 2.16.2, certificate update JSON-RPC message handling does not validate that the sender is a trusted endpoint. An unauthenticated network attacker able to conne
Noch keine Analyse zu CVE-2026-61550
Sei der Erste: Einschätzung, Betroffenheit, Workaround oder PoC — mit Antworten im Thread.