ntop has 6 CVEs on record. Disclosure cadence is accelerating: 6 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 6. The median CVSS is 7.8 (high). None have a confirmed exploitation report. The most common weakness class is CWE-862 (4). Most affected products: ntopng (5), nDPI (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.8
- Publish → KEV
- —
- Last 90 days
- 6 prev 0
Worst active — by depth score
CVE-2026-86091High· 7.1ntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing authenticated non-administrators to delete all host pools and member bindings51CVE-2026-84990High· 8.8ntopng is a web-based network traffic monitoring application48CVE-2026-82412High· 8.8ntopng is a web-based network traffic monitoring application48CVE-2026-83621High· 8.1ntopng is a web-based network traffic monitoring application45CVE-2026-86098High· 7.4ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerability in the ndpi_json_string_escape function that writes beyond caller-supplied buffer boundaries41
ntop vulnerabilities
CVEs affecting ntop, newest first. Open any entry for full detail, references, and exploit status.
6 CVEsRSS
CVE-2026-83621High· 8.1ntopng is a web-based network traffic monitoring application
ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, POST /lua/rest/v2/edit/system/edit_blacklist.lua in scripts/lua/rest/v2/edit/system/edit_blacklist.lua lacks an administrator check and calls lists_utils.…
CVE-2026-84990High· 8.8ntopng is a web-based network traffic monitoring application
ntopng is a web-based network traffic monitoring application. Prior to 6.7.260718, scripts/lua/rest/v2/get/system/configurations/list_available_backups.lua and scripts/lua/rest/v2/get/system/configurations/download_backup.lua allow any a…
CVE-2026-82412High· 8.8ntopng is a web-based network traffic monitoring application
ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, the vulnerability-scan endpoints scripts/lua/rest/v2/add/host/to_scan.lua and scripts/lua/rest/v2/exec/host/schedule_vulnerability_scan.lua accept the sca…
CVE-2026-86098High· 7.4ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerability in the ndpi_json_string_escape function that writes beyond caller-supplied buffer boundaries
ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerability in the ndpi_json_string_escape function that writes beyond caller-supplied buffer boundaries. Attackers can trigger the overflow by supplying crafted network pack…
CVE-2026-86090High· 7.1ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 handlers
ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 handlers. Authenticated non-administrator users can issue POST requests to irreversibly delete all configured notification endp…
CVE-2026-86091High· 7.1PoCntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing authenticated non-administrators to delete all host pools and member bindings
ntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing authenticated non-administrators to delete all host pools and member bindings. Attackers can issue POST requests to the delete pools endp…