VulnSea

Elastic has 34 CVEs on record between 2024 and 2026. Disclosure cadence is accelerating: 28 in the last 90 days against 1 in the 90 before. The busiest recent month was September 2026 with 14. The median CVSS is 6.5 (medium). None have a confirmed exploitation report. The dominant weakness classes are CWE-400 (10) and CWE-863 (4). Most affected products: Elasticsearch (12), Kibana (12), github.com/elastic/apm-server (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.5
Publish → KEV
—
Last 90 days
28 prev 1

Products

  • Elasticsearch 12
  • Kibana 12
  • github.com/elastic/apm-server 2
  • github.com/elastic/beats/v7 2
  • elastic_cloud_on_kubernetes 1
  • endpoint_security 1
34
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Elastic vulnerabilities (CVEs) — page 2 · VulnSea