Icinga has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 8.6 (high), with 1 rated critical.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.6
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
Icinga vulnerabilities
CVEs affecting Icinga, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-61550Critical· 9.8Icinga 2 is an open source monitoring system
Icinga 2 is an open source monitoring system. From 2.8 until 2.14.9, 2.15.4, and 2.16.2, certificate update JSON-RPC message handling does not validate that the sender is a trusted endpoint. An unauthenticated network attacker able to co…
CVE-2026-61551High· 8.6Icinga 2 is an open source monitoring system
Icinga 2 is an open source monitoring system. Prior to 2.14.9, 2.15.4, and 2.16.2, parsing deeply nested JSON can exhaust the call stack because nesting depth is not bounded. The affected JSON parsing paths are reachable by unauthenticat…
CVE-2026-61552High· 7.2Icinga 2 is an open source monitoring system
Icinga 2 is an open source monitoring system. From 2.4 until 2.14.9, 2.15.4, and 2.16.2, the /v1/objects API writes attacker-controlled template names into generated configuration without escaping them. An authenticated ApiUser with an o…