CVE Tools

Checkmk

122 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Checkmk, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.

Checkmk CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Checkmk CVEs per month
MonthCVEs
2024-103
2024-111
2024-121
2025-010
2025-021
2025-031
2025-042
2025-054
2025-060
2025-071
2025-080
2025-090
2025-104
2025-113
2025-122
2026-010
2026-022
2026-036
2026-046
2026-051
2026-065
2026-073
2026-083
2026-094

Severity

How the 122 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical11%
  • High4036%
  • Medium6256%
  • Low76%

Latest CVEs

The 15 most recently published vulnerabilities affecting Checkmk.

  1. CVE-2026-90990Livestatus injection via monitoring filter values—
  2. CVE-2026-92882Redact SNMP community, SNMPv3 pass phrases, and IPMI password in host config REST API GET responses—
  3. CVE-2026-77021Missing decompression size limit in agent receiver allows memory exhaustion via push agent data—
  4. CVE-2026-15937Agent receiver certificate confusion allows authentication with a certificate issued for another endpoint—
  5. CVE-2026-17548Missing authorization for viewing background jobs—
  6. CVE-2026-15576Agent receiver accepts mTLS requests without a client certificate—
  7. CVE-2026-7485Frozen BI aggregations leak host and service names to unauthorized users—
  8. CVE-2026-15227Missing Authorization Allows Editing of Foreign Reports—
  9. CVE-2026-8593Fix Business Intelligence API Pack permission—
  10. CVE-2026-14852mk_sap_hana: Privilege escalation via crafted sapstartsrv process name—
  11. CVE-2026-9549Fix XSS in service discovery active check output4.8
  12. CVE-2026-8833XSS in urls5.4
  13. CVE-2026-8078Fix stored XSS in global settings change log4.8
  14. CVE-2026-7765User Messages widget leaked issuer messages on shared dashboards5.3
  15. CVE-2026-7186Fix stored XSS in URL dashboard widget via dangerous URI schemes5.4

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store