Checkmk GmbH maintains a focused monitoring and observability platform that, despite its narrow product scope, occupies a prominent position in enterprise IT operations infrastructure. The vendor's vulnerability footprint concentrates within its core Checkmk product and is characterized by web-application-oriented weakness classes including cross-site scripting variants, input-validation flaws, and improper handling of sensitive information in logs—typical of browser-facing configuration and dashboard interfaces. The durable pattern reflects the challenge of securing feature-rich web UIs that handle both user input and system data across distributed monitoring deployments. Current exposure counts, severity breakdown, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Checkmk GmbH over time
Of all the CVEs published by Checkmk GmbH as a CNA, 86.1% affect products that Checkmk GmbH develops as a vendor.
Of all the CVEs published that affect products developed by Checkmk GmbH, 89.2% are self-published by Checkmk GmbH as a CNA.
Signals from CVEs in this vendor scope (111 CVEs).
111 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-14955MEDIUM Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, which allows remote attackers to obtain sensitive user informat | Oct 2, 2017 | 5.9 | 37 | NO | YES |
CVE-2021-40905HIGH The web management console of CheckMK Enterprise Edition (versions 1.5.0 to 2.0.0p9) does not properly sanitise the uploading of ".mkp" files, which are Extension Packages, making | Mar 25, 2022 | 8.8 | 32 | NO | NO |
CVE-2021-40904HIGH The web management console of CheckMK Raw Edition (versions 1.5.0 to 1.6.0) allows a misconfiguration of the web-app Dokuwiki (installed by default), which allows embedded php code | Mar 25, 2022 | 8.8 | 32 | NO | NO |
CVE-2026-33456HIGH Livestatus injection in the notification test mode in Checkmk <2.5.0b4 and <2.4.0p26 allows an authenticated user with access to the notification test page to inject arbitrary Live | Apr 10, 2026 | 7.6 | 30 | NO | NO |
CVE-2024-47091HIGH Privilege escalation in the mk_mysql agent plugin on Windows in Checkmk <2.4.0p29, <2.3.0p47, and 2.2.0 (EOL) allows a local unprivileged user able to create a Windows service whos | May 13, 2026 | 7.8 | 29 | NO | NO |
CVE-2022-48317CRITICAL Expired sessions were not securely terminated in the RestAPI for Tribe29's Checkmk <= 2.1.0p10 and Checkmk <= 2.0.0p28 allowing an attacker to use expired session tokens when commu | Feb 20, 2023 | 9.8 | 29 | NO | NO |
CVE-2022-46836HIGH PHP code injection in watolib auth.php and hosttags.php in Tribe29's Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allows an attacker to inject and execute PHP | Feb 20, 2023 | 8.8 | 29 | NO | NO |
CVE-2026-24096HIGH Insufficient permission validation on multiple REST API Quick Setup endpoints in Checkmk 2.5.0 (beta) before version 2.5.0b2 and 2.4.0 before version 2.4.0p25 allows low-privileged | Apr 1, 2026 | 8.8 | 28 | NO | NO |
CVE-2026-8593MEDIUM Improper permission enforcement in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows users without permissions to view and | Jul 21, 2026 | 5.3 | 27 | NO | NO |
CVE-2026-14852MEDIUM Privilege escalation in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows a local unprivileged user to execute arbitrary c | Jul 14, 2026 | 5.2 | 27 | NO | NO |
Signals from CVEs in this vendor scope (111 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Checkmk GmbH.
Media articles that mention a CVE ID that affects a product developed by Checkmk GmbH — matched by CVE ID, not by vendor name.