Icinga2
12 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Icinga2, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
Icinga2 CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 1 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 1 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 3 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 1 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 3 |
Severity
How the 12 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical3
- High5
- Medium4
Latest CVEs
The 12 most recently published vulnerabilities affecting Icinga2.
- CVE-2026-61552Icinga 2 DSL Injection via Unescaped Import Template Name7.2
- CVE-2026-61551Icinga 2: Stack overflow via deeply nested JSON objects8.6
- CVE-2026-61550Icinga 2: Improper access control for JSON-RPC update certificate messages9.8
- CVE-2026-24413Icinga has insecure permission of %ProgramData%\icinga2\var on Windows5.5
- CVE-2025-61909Icinga 2 signals sent as root to processes based on PID file written by the Icinga 2 daemon user4.4
- CVE-2025-61908Icinga 2 Denial of Service (DoS) By Dereferencing Invalid Reference6.5
- CVE-2025-61907Icinga 2 API users could access restricted values in filter expressions6.5
- CVE-2025-48057Icinga 2 certificate renewal might incorrectly renew an invalid certificate9.8
- CVE-2024-49369Icinga 2 has a TLS Certificate Validation Bypass for JSON-RPC and HTTP API Connections9.8
- CVE-2021-37698Missing TLS service certificate validation in GelfWriter, ElasticsearchWriter, InfluxdbWriter and Influxdb2Writer7.5
- CVE-2021-32743Passwords used to access external services inadvertently exposed through API8.8
- CVE-2021-32739Results of queries for ApiListener objects include the ticket salt which allows in turn to steal (more privileged) identities8.8
Product grouping is registry-driven, with AI assist and human review. How it works