Wazuh maintains a security monitoring and threat-detection platform centered on a focused set of products including its core agent-manager system, dashboard, and Kibana integration components. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and cluster around memory-safety and input-handling weaknesses such as NULL-pointer dereferences, buffer overflows, path-traversal flaws, and unchecked return values that are characteristic of security-critical monitoring software. The exposure concentrates in the Wazuh platform and its dashboard interfaces, which sit in sensitive positions within infrastructure monitoring and log-aggregation architectures. Defenders should prioritize patching for this vendor given the elevated severity profile and the privileged access monitoring systems typically require; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wazuh over time
Signals from CVEs in this vendor scope (50 CVEs).
50 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-24016CRITICAL Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 and prior to version 4.9.1, an unsafe deserialization vulner | Feb 10, 2025 | 9.9 | 98 | YES | YES |
CVE-2023-50260HIGH Wazuh is a free and open source platform used for threat prevention, detection, and response. A wrong validation in the `host_deny` script allows to write any string in the `hosts. | Apr 19, 2024 | 8.8 | 47 | NO | NO |
CVE-2026-56699CRITICAL Wazuh Manager before 5.0.0-beta3 fails to escape the DataValue.index field when constructing OpenSearch bulk requests, allowing enrolled agents to inject arbitrary NDJSON operation | Jul 15, 2026 | 10.0 | 41 | NO | NO |
CVE-2026-30893CRITICAL Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.4.0 to before version 4.14.4, a path traversal vulnerability in Wazuh's | Apr 29, 2026 | 9.9 | 40 | NO | NO |
CVE-2026-25769CRITICAL Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.0.0 through 4.14.2 have a Remote Code Execution (RCE) vulnerability due to | Mar 17, 2026 | 9.1 | 40 | NO | NO |
CVE-2026-40106HIGH Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.6.0 and above prior to 4.14.5 contain a heap-based buffer overflow vulnerab | Jul 17, 2026 | 7.8 | 33 | NO | NO |
CVE-2026-39359HIGH Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.0.0 through 4.10.3 and 4.11.0 through 4.14.4, a logic flaw affects the W | Jul 17, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-34150HIGH Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 1.0.0 and above, prior to 4.14.5, a heap buffer overflow in wazuh-analysis | Jul 17, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-33434HIGH Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.6.0 and above, prior to 4.14.5, a logic error in CheckRateLimitsMiddlewa | Jul 17, 2026 | 7.1 | 31 | NO | NO |
CVE-2026-28221HIGH Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.8.0 to before version 4.14.4, a stack-based buffer overflow exists in p | Apr 29, 2026 | 8.2 | 31 | NO | NO |
Signals from CVEs in this vendor scope (50 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wazuh.
Media articles that mention a CVE ID that affects a product developed by Wazuh — matched by CVE ID, not by vendor name.