CVE Tools

Icinga

31 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Icinga, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.

Icinga CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Icinga CVEs per month
MonthCVEs
2024-100
2024-111
2024-120
2025-010
2025-020
2025-030
2025-040
2025-051
2025-060
2025-070
2025-080
2025-090
2025-103
2025-110
2025-120
2026-011
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 31 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical310%
  • High1239%
  • Medium1548%
  • Low13%

Latest CVEs

The 15 most recently published vulnerabilities affecting Icinga.

  1. CVE-2026-24413Icinga has insecure permission of %ProgramData%\icinga2\var on Windows5.5
  2. CVE-2025-61909Icinga 2 signals sent as root to processes based on PID file written by the Icinga 2 daemon user4.4
  3. CVE-2025-61908Icinga 2 Denial of Service (DoS) By Dereferencing Invalid Reference6.5
  4. CVE-2025-61907Icinga 2 API users could access restricted values in filter expressions6.5
  5. CVE-2025-48057Icinga 2 certificate renewal might incorrectly renew an invalid certificate9.8
  6. CVE-2024-49369Icinga 2 has a TLS Certificate Validation Bypass for JSON-RPC and HTTP API Connections9.8
  7. CVE-2024-24820Icinga Director configuration is susceptible to Cross-Site Request Forgery8.3
  8. CVE-2021-37698Missing TLS service certificate validation in GelfWriter, ElasticsearchWriter, InfluxdbWriter and Influxdb2Writer7.5
  9. CVE-2021-32743Passwords used to access external services inadvertently exposed through API8.8
  10. CVE-2021-32739Results of queries for ApiListener objects include the ticket salt which allows in turn to steal (more privileged) identities8.8
  11. CVE-2021-32747Custom variable protection and blacklists can be circumvented5.3
  12. CVE-2021-32746Possible path traversal by use of the `doc` module5.3
  13. CVE-2020-29663Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring the CRL. This issue is fixed in Icinga 2 v2.11.8 and v2.1...9.1
  14. CVE-2020-14004An issue was discovered in Icinga2 before v2.12.0-rc1. The prepare-dirs script (run as part of the icinga2 systemd service) executes chmod 2750 /run/icinga2/cmd. /run/icinga2 is under control of an...7.8
  15. CVE-2018-6534An issue was discovered in Icinga 2.x through 2.8.1. By sending specially crafted messages, an attacker can cause a NULL pointer dereference, which can cause the product to crash.6.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store