VulnSea

Checkmk GmbH has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 5.3 (medium).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
5.3
Publish → KEV
Last 90 days
3 prev 0

Products

  • Checkmk 3
3
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

Checkmk GmbH vulnerabilities

CVEs affecting Checkmk GmbH, newest first. Open any entry for full detail, references, and exploit status.

3 CVEsRSS

CVE-2026-92882Low· 2.3
today

Insufficiently protected credentials in the host and folder configuration endpoints of the REST API in Checkmk <2.5.0p15, <2.4.0p37, <2.3.0p51 and 2.2.0 (EOL) allows an authenticated user who may view a host's configuration to read store…

Insufficiently protected credentials in the host and folder configuration endpoints of the REST API in Checkmk <2.5.0p15, <2.4.0p37, <2.3.0p51 and 2.2.0 (EOL) allows an authenticated user who may view a host's configuration to read store…

SunlitCheckmk GmbH · Checkmkvia NVD
CVE-2026-90990Medium· 5.3
today

Improper neutralization of newlines in filter values in the monitoring host and service list APIs in Checkmk <2.5.0p14 allows an authenticated user to inject additional Livestatus query headers, bypassing object visibility restrictions i…

Improper neutralization of newlines in filter values in the monitoring host and service list APIs in Checkmk <2.5.0p14 allows an authenticated user to inject additional Livestatus query headers, bypassing object visibility restrictions i…

SunlitCheckmk GmbH · Checkmkvia NVD
CVE-2026-77021Medium· 5.3
yesterday

Improper handling of highly compressed data (data amplification) in Checkmk <2.5.0p14, <2.4.0p37, <2.3.0p51 and 2.2.0 (EOL) allows an attacker who controls a host registered for push mode to exhaust the memory of the agent receiver by se…

Improper handling of highly compressed data (data amplification) in Checkmk <2.5.0p14, <2.4.0p37, <2.3.0p51 and 2.2.0 (EOL) allows an attacker who controls a host registered for push mode to exhaust the memory of the agent receiver by se…

SunlitCheckmk GmbH · Checkmkvia NVD
Checkmk GmbH vulnerabilities (CVEs) · VulnSea