Icinga operates a well-regarded open-source monitoring and observability platform that spans a core engine, web interfaces, and integrations, positioning itself as a prominent member of the infrastructure-monitoring landscape despite a modestly sized product portfolio. Vulnerabilities affecting the vendor frequently acquire public exploit code and concentrate in the web-facing components—particularly the Icinga Web 2 interface and related administrative dashboards—where they manifest as input-validation and authentication weaknesses including cross-site scripting, cross-site request forgery, path traversal, and improper certificate validation. These weakness classes reflect the web-application and user-input handling demands of a distributed monitoring platform that often sits in privileged network positions with access to critical operational data. Defenders should treat Icinga updates as moderately urgent for exposed or internet-connected instances, since the platform's administrative scope and the tendency toward exploit availability warrant timely remediation. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Icinga over time
Signals from CVEs in this vendor scope (49 CVEs).
49 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24716HIGH Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Unauthenticated users can leak the contents of files of the local system accessible t | Mar 8, 2022 | 7.5 | 87 | NO | YES |
CVE-2012-6096HIGH Multiple stack-based buffer overflows in the get_history function in history.cgi in Nagios Core before 3.4.4, and Icinga 1.6.x before 1.6.2, 1.7.x before 1.7.4, and 1.8.x before 1. | Jan 22, 2013 | 7.5 | 79 | NO | YES |
CVE-2013-7108MEDIUM Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote authenticated users to obtain se | Jan 15, 2014 | 5.5 | 63 | NO | YES |
CVE-2022-24715HIGH Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Authenticated users, with access to the configuration, can create SSH resource files | Mar 8, 2022 | 8.8 | 47 | NO | YES |
CVE-2011-2179MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in config.c in config.cgi in (1) Nagios 3.2.3 and (2) Icinga before 1.4.1 allow remote attackers to inject arbitrary web script | Jun 14, 2011 | 4.3 | 40 | NO | YES |
CVE-2024-49369CRITICAL Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. The TLS certificate valid | Nov 12, 2024 | 9.8 | 29 | NO | NO |
CVE-2020-29663CRITICAL Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring the CRL. This issue is fixed in Icinga 2 | Dec 15, 2020 | 9.1 | 29 | NO | NO |
CVE-2025-48057CRITICAL Icinga 2 is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. Prior to versions 2.12. | May 27, 2025 | 9.8 | 28 | NO | NO |
CVE-2021-32739HIGH Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. From version 2.4.0 throug | Jul 15, 2021 | 8.8 | 28 | NO | NO |
CVE-2018-18249CRITICAL Icinga Web 2 before 2.6.2 allows injection of PHP ini-file directives via vectors involving environment variables as the channel to send information to the attacker, such as a name | Dec 17, 2018 | 9.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (49 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Icinga.
Media articles that mention a CVE ID that affects a product developed by Icinga — matched by CVE ID, not by vendor name.