icinga has 7 CVEs on record between 2025 and 2026. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 6.5 (medium), with 1 rated critical. None have a confirmed exploitation report. Most affected products: icinga (3), icinga2 (3), icinga_db_web (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.5
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
Products
- icinga 3
- icinga2 3
- icinga_db_web 1
Worst active — by depth score
CVE-2026-61550Critical· 9.8Icinga 2 is an open source monitoring system54CVE-2026-61551High· 8.6Icinga 2 is an open source monitoring system47CVE-2026-61552High· 7.2Icinga 2 is an open source monitoring system40CVE-2025-61908Medium· 6.5Icinga 2 is an open source monitoring system36CVE-2025-61907Medium· 6.5Icinga 2 is an open source monitoring system36
icinga vulnerabilities
CVEs affecting icinga, newest first. Open any entry for full detail, references, and exploit status.
7 CVEsRSS
CVE-2026-61550Critical· 9.8Icinga 2 is an open source monitoring system
Icinga 2 is an open source monitoring system. From 2.8 until 2.14.9, 2.15.4, and 2.16.2, certificate update JSON-RPC message handling does not validate that the sender is a trusted endpoint. An unauthenticated network attacker able to co…
CVE-2026-61551High· 8.6Icinga 2 is an open source monitoring system
Icinga 2 is an open source monitoring system. Prior to 2.14.9, 2.15.4, and 2.16.2, parsing deeply nested JSON can exhaust the call stack because nesting depth is not bounded. The affected JSON parsing paths are reachable by unauthenticat…
CVE-2026-61552High· 7.2Icinga 2 is an open source monitoring system
Icinga 2 is an open source monitoring system. From 2.4 until 2.14.9, 2.15.4, and 2.16.2, the /v1/objects API writes attacker-controlled template names into generated configuration without escaping them. An authenticated ApiUser with an o…
CVE-2025-61909Medium· 4.4Icinga 2 is an open source monitoring system
Icinga 2 is an open source monitoring system. From 2.10.0 to before 2.15.1, 2.14.7, and 2.13.13, the safe-reload script (also used during systemctl reload icinga2) and logrotate configuration shipped with Icinga 2 read the PID of the mai…
CVE-2025-61908Medium· 6.5Icinga 2 is an open source monitoring system
Icinga 2 is an open source monitoring system. From 2.10.0 to before 2.15.1, 2.14.7, and 2.13.13, when creating an invalid reference, such as a reference to null, dereferencing results in a segmentation fault. This can be used by any API …
CVE-2025-61907Medium· 6.5Icinga 2 is an open source monitoring system
Icinga 2 is an open source monitoring system. In Icinga 2 versions 2.4 through 2.15.0, filter expressions provided to the various /v1/objects endpoints could access variables or objects that would otherwise be inaccessible for the user. …
CVE-2025-61789Medium· 5.3Icinga DB Web provides a graphical interface for Icinga monitoring
Icinga DB Web provides a graphical interface for Icinga monitoring. Before 1.1.4 and 1.2.3, an authorized user with access to Icinga DB Web, can use a custom variable in a filter that is either protected by icingadb/protect/variables or …