CVE-2026-25769Disclosure(wazuh / wazuh)

CRITICALCVSS 9.1 · CRITICAL

Exploitation observed; activity peaked at 6 mentions and remains active

Immediate actions

  • Patch wazuh wazuh systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.0.0 through 4.14.2 have a Remote Code Execution (RCE) vulnerability due to Deserialization of Untrusted Data). All Wazuh deployments using cluster mode (master/worker architecture) and any organization with a compromised worker node (e.g., through initial access, insider threat, or supply chain attack) are impacted. An attacker who gains access to a worker node (through any means) can achieve full RCE on the master node with root privileges. Version 4.14.3 fixes the issue.

8.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wazuh

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 34 mentions across 18 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 5 signals
  • PoC mentioned or linked in 13 signals
  • Patch or workaround mentioned in 8 signals
  • Technical details provided in 29 signals
  • Disclosure: 11 classified signals
  • General: 8 classified signals
  • Peaked 16d ago at 6 mentions (2026-03-18); latest day: 1
  • 34 total mentions across 18 days

Affected systems

Vendors
Products
wazuh

Deep dive

Activity timeline34 mentions / 18d
02356Mentions · 2026-03-17: 5Mentions · 2026-03-18: 6Mentions · 2026-03-23: 1Mentions · 2026-03-24: 1Mentions · 2026-03-26: 1Mentions · 2026-03-31: 2Mentions · 2026-04-01: 2Mentions · 2026-04-02: 2Mentions · 2026-04-03: 3Mentions · 2026-04-04: 1Mentions · 2026-04-07: 1Mentions · 2026-04-08: 3Mentions · 2026-04-12: 1Mentions · 2026-04-15: 1Mentions · 2026-05-10: 1Mentions · 2026-05-18: 1Mentions · 2026-05-29: 1Mentions · 2026-06-15: 1PoC Mentioned / Linked · 2026-03-17: 1PoC Mentioned / Linked · 2026-03-18: 4PoC Mentioned / Linked · 2026-03-23: 1PoC Mentioned / Linked · 2026-03-31: 1PoC Mentioned / Linked · 2026-04-02: 1PoC Mentioned / Linked · 2026-04-04: 1PoC Mentioned / Linked · 2026-04-08: 1PoC Mentioned / Linked · 2026-04-15: 1PoC Mentioned / Linked · 2026-05-18: 1PoC Mentioned / Linked · 2026-06-15: 1Exploit Tool / Code · 2026-03-17: 1Exploit Tool / Code · 2026-03-18: 4Active Exploitation · 2026-04-01: 1Patch / Workaround · 2026-03-17: 2Patch / Workaround · 2026-03-23: 1Patch / Workaround · 2026-03-24: 1Patch / Workaround · 2026-04-01: 1Patch / Workaround · 2026-04-08: 1Patch / Workaround · 2026-04-12: 1Patch / Workaround · 2026-06-15: 1Technical Details · 2026-03-17: 5Technical Details · 2026-03-18: 6Technical Details · 2026-03-23: 1Technical Details · 2026-03-24: 1Technical Details · 2026-04-01: 1Technical Details · 2026-04-02: 2Technical Details · 2026-04-03: 3Technical Details · 2026-04-04: 1Technical Details · 2026-04-07: 1Technical Details · 2026-04-08: 3Technical Details · 2026-04-12: 1Technical Details · 2026-04-15: 1Technical Details · 2026-05-10: 1Technical Details · 2026-05-18: 1Technical Details · 2026-06-15: 103-1703-1803-2303-2403-2603-3104-0104-0204-0304-0404-0704-0804-1204-1505-1005-1805-2906-15
Signal classification5 categories
Disclosure
1132.4%
PoC
926.5%
General
823.5%
Patch
411.8%
Exploit
25.9%
Referenced assets33 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-175
Disclosure4Patch1
2026-03-186
Disclosure2Exploit1PoC3
2026-03-231
PoC1
2026-03-241
Patch1
2026-03-261
General1
2026-03-312
General1PoC1
2026-04-012
Exploit1General1
2026-04-022
General1PoC1
2026-04-033
Disclosure2General1
2026-04-041
PoC1
2026-04-071
General1
2026-04-083
Disclosure2Patch1
2026-04-121
General1
2026-04-151
PoC1
2026-05-101
Disclosure1
2026-05-181
PoC1
2026-05-291
General1
2026-06-151
Patch1
Full discourse20 posts
  • Carlos Vieira (lynx)@carlos_crowsec
    Disclosure

    CVE-2026-25769: Wazuh Post-Auth RCE Our team discovered an insecure deserialization vulnerability in the Wazuh Cluster that enables remote command execution via a worker node, potentially leading to full cluster compromise. CVSS: 9.1 (authentication required) Wazuh - Security Advisories: https://github.com/wazuh/wazuh/security/advisories/GHSA-3gm7-962f-fxw5 PoC: https://github.com/hakaioffsec/CVE-2026-25769 Blog: https://hakaisecurity.io/cve-2026-25769-rce-via-insecure-deserialization-in-wazuh-cluster-remote-command-execution-through-cluster-protocol/research-blog/

    Post summary

    The post announces a newly discovered insecure deserialization flaw in Wazuh Cluster (CVE-2026-25769) that can lead to remote command execution, provides a PoC, and references a vendor advisory for patching.

    24411488018.1K
    3.1K followersView on X
  • VLadimiR@Dz10Chiheb
    PoC

    CVE-2026-25769 - Remote Code Execution via Insecure Deserialization in Wazuh Cluster https://github.com/hakaioffsec/CVE-2026-25769 https://t.co/IrBEEgbXvF

    Post summary

    A GitHub repository hosts a proof‑of‑concept exploit for CVE‑2026‑25769, enabling remote code execution via insecure deserialization in Wazuh Cluster; no active exploitation or patch information is provided.

    0320116628.8K
    491 followersView on X
  • blueblue@piedpiper1616
    Exploit

    GitHub - hakaioffsec/CVE-2026-25769: Remote Code Execution via Insecure Deserialization in Wazuh Cluster · GitHub - https://github.com/hakaioffsec/CVE-2026-25769

    Post summary

    The GitHub repository contains exploit code that demonstrates Remote Code Execution via insecure deserialization in Wazuh clusters, providing a functional PoC but no evidence of active exploitation or mitigation.

    010030132.0K
    5.5K followersView on X
  • TAGHREED@taghhred
    General

    TryHackMe: • SOC L1 Path : https://tryhackme.com/path/outline/soclevel1 • Digital Forensics and Incident Response : https://tryhackme.com/module/digital-forensics-and-incident-response • Digital Forensics Case B4DM755 : https://tryhackme.com/room/caseb4dm755 • Wazuh : https://tryhackme.com/room/wazuhct • Wazuh: CVE-2026-25769 : https://tryhackme.com/room/wazuhcve202625769 Cyberdefenders: • HawkEye lab : https://cyberdefenders.org/blueteam-ctf-challenges/hawkeye/ • get DPF Lab : https://cyberdefenders.org/blueteam-ctf-challenges/getpdf/

    Post summary

    The text lists TryHackMe and Cyberdefenders learning resources, including a reference to CVE‑2026‑25769, but offers no technical or operational detail regarding the vulnerability.

    21016321.3K
    551 followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Wazuh patches two critical 9.1 CVSS flaws (CVE-2026-25769 & CVE-2026-25770) allowing total cluster takeover. Upgrade to v4.14.3 now to stay protected. #Wazuh #CyberSecurity #InfoSec #Vulnerability #RCE #PrivEsc #PatchNow #OpenSource #ThreatIntel https://securityonline.info/wazuh-security-vulnerabilities-rce-privilege-escalation-patch-v4-14-3/ https://t.co/tAYsLCszNr

    Post summary

    Wazuh has released patch v4.14.3 to address two critical CVSS 9.1 vulnerabilities (CVE‑2026‑25769 and CVE‑2026‑25770) that allow total cluster takeover, and urges users to upgrade immediately.

    05028151.7K
    10.9K followersView on X
  • Clandestine@akaclandestine
    PoC

    GitHub - hakaioffsec/CVE-2026-25769: Remote Code Execution via Insecure Deserialization in Wazuh Cluster · GitHub https://github.com/hakaioffsec/CVE-2026-25769

    Post summary

    The GitHub repository provides a proof‑of‑concept demonstrating RCE via insecure deserialization in Wazuh, but there is no evidence of active exploitation or an available patch.

    09024122.1K
    56.2K followersView on X
  • NullSecurityX@NullSecurityX
    Disclosure

    Critical RCE in Wazuh Cluster (CVE-2026-25769) A single compromised worker node can lead to ROOT access on the master ⚠️ 🎯 Learn how it works, how to detect it, and how to defend against it. 👇 Watch now: http://youtu.be/4ZCe1FkjmXA #BugBounty #CyberSecurity

    Post summary

    The post announces a critical RCE in Wazuh Cluster (CVE‑2026‑25769) that can give root access from a compromised worker node, with a video walk‑through linked to explain the issue.

    04028112.9K
    11.8K followersView on X
  • Nicolas Krassas@Dinosn
    Disclosure

    CVE-2026-25769: Critical Remote Code Execution in Wazuh via Unsafe Deserialization https://www.resecurity.com/blog/article/cve-2026-25769-critical-remote-code-execution-in-wazuh-via-unsafe-deserialization

    Post summary

    A new CVE-2026-25769 critical RCE vulnerability in Wazuh via unsafe deserialization has been disclosed, with a blog post linking to more details.

    0502492.7K
    157.2K followersView on X
  • NullSecurityX@NullSecurityX
    PoC

    NEW Videooo:🚨 Critical RCE in Wazuh Cluster (CVE-2026-25769) A single compromised worker node can lead to ROOT access on the master ⚠️ 🎯 Learn how it works, how to detect it, and how to defend against it. 👇 Watch now: https://youtu.be/4ZCe1FkjmXA #BugBounty #CyberSecurity

    Post summary

    The post shares a video that demonstrates how CVE-2026-25769 enables a single compromised worker node to achieve root access on a Wazuh master, offering detection and defense guidance.

    11012102.6K
    11.8K followersView on X
  • Co11ateral@co11ateral
    PoC

    CVE-2026-25769 - Remote Code Execution via Insecure Deserialization in Wazuh Cluster A proof-of-concept exploit for CVE-2026-25769, a Remote Code Execution via Insecure Deserialization in Wazuh Cluster https://github.com/hakaioffsec/CVE-2026-25769 #cybersecurity #redteam #blueteam

    Post summary

    A proof‑of‑concept exploit for CVE‑2026‑25769, an RCE via insecure deserialization in Wazuh, is published on GitHub, with no evidence of live attacks or patches mentioned.

    0601121.0K
    4.5K followersView on X
  • TheGentlemanHacker@mld_77
    PoC

    I just completed Wazuh: CVE-2026-25769 room on TryHackMe! Learn how attackers exploit CVE-2026-25769 in Wazuh to gain RCE. https://tryhackme.com/room/wazuhcve202625769?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=5f9b52519f63ac139bb7e225 #tryhackme via @tryhackme

    Post summary

    A user shares completing a TryHackMe room that demonstrates how to exploit CVE-2026-25769 in Wazuh for remote code execution, providing a proof‑of‑concept framework.

    01051194
    1.7K followersView on X
  • Lucas@lucasverdan
    Disclosure

    🛑 Critical Wazuh cluster flaw can lead to remote code execution on the master node. CVE-2026-25769 abuses insecure deserialization in cluster traffic. If an attacker compromises a worker, they may be able to execute arbitrary commands on the master. That puts the monitoring plane itself at risk, including centralized telemetry, rules, and response trust. 🔗 Details → https://invaders.ie/resources/blog/vulnerability/cve-2026-25769-wazuh-cluster-flaw-enables-remote-code-execution

    Post summary

    A new critical Wazuh vulnerability (CVE-2026-25769) that allows remote code execution via insecure deserialization on the master node has been disclosed, with no evidence of exploitation or patch availability.

    02030427
    309 followersView on X
  • Constantin Milos ♏@Tinolle infosec.exchange@Tinolle1955
    Disclosure

    CVE-2026-25769 – RCE via Insecure Deserialization in Wazuh Cluster – Remote Command Execution through Cluster Protocol https://hakaisecurity.io/cve-2026-25769-rce-via-insecure-deserialization-in-wazuh-cluster-remote-command-execution-through-cluster-protocol/research-blog/

    Post summary

    The blog post announces CVE-2026-25769, detailing a remote command execution flaw stemming from insecure deserialization in Wazuh's cluster protocol, but it does not provide evidence of active exploitation, a PoC, or a remediation.

    01030239
    4.6K followersView on X
  • Ahmed Salah (00xA7md)@00xA7md
    Exploit

    🚨 Wazuh RCE (CVE-2026-25769) Unsafe JSON deserialization in master → arbitrary Python exec via object hooks (no allowlist). Exploit: compromised worker → crafted JSON → "import" → RCE as root. CVSS 9.1 Patch: 4.14.3 Treat inter-node comms as untrusted https://www.facebook.com/share/v/1DDYCiMNvU/ https://t.co/JjDyIVDTVP

    Post summary

    The post highlights CVE-2026-25769, detailing how unsafe JSON deserialization allows root-level Python execution, confirming active exploitation, providing a patch (4.14.3), and a high CVSS score of 9.1.

    00030200
    139 followersView on X
  • Jason Abernathy@jlabernathy
    General

    CISA dropped 7 ICS advisories today - Hitachi Energy, Mitsubishi Electric, CyberData. If your OT and IT share a network segment, this is your Thursday threat landscape. Concurrent Cyble report also flagged CVE-2026-25769, a critical RCE in Wazuh cluster deployments. Patch windows do not care about conference schedules. #ICS #OT #Cybersecurity

    Post summary

    The post highlights the discovery of CVE-2026-25769—a critical remote code execution vulnerability in Wazuh cluster deployments—without providing any PoC, exploit, patch, or evidence of active exploitation.

    1001085
    386 followersView on X
  • Himadri Singh@LittleSun4lower
    PoC

    I just completed Wazuh: CVE-2026-25769 room on TryHackMe! Learn how attackers exploit CVE-2026-25769 in Wazuh to gain RCE. https://tryhackme.com/room/wazuhcve202625769?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=66457951599dd28bfb000ded #tryhackme via @tryhackme #tryhackme #vulnerability #cve #wazuh #learning

    Post summary

    The tweet promotes a TryHackMe learning room that demonstrates how to exploit CVE‑2026‑25769 in Wazuh for remote code execution, providing a PoC but no detailed code, patches, or evidence of active exploitation.

    0000189
    13 followersView on X
  • Cydome Security 🛡️⚓@cydome
    Disclosure

    ▶️ Remote Code Execution in Wazuh Server (CVE-2026-25769, CVSS 9.1) A critical deserialization vulnerability in Wazuh server, a central component of the open-source Wazuh SIEM/XDR platform, was published, allowing an attacker who has compromised a worker node to achieve

    Post summary

    A new critical deserialization vulnerability (CVE-2026-25769) in Wazuh server, rated CVSS 9.1 and permitting remote code execution, has been disclosed but no PoC, exploit, or mitigation details are provided.

    1000076
    145 followersView on X
  • Djalil Ayed@DjalilAyed
    PoC

    🐥 New room Wazuh: CVE-2026-25769 from @tryhackme 🍊 Learn how attackers exploit CVE-2026-25769 in Wazuh to gain RCE. 🥦 Room link: https://tryhackme.com/room/wazuhcve202625769 🌽 Task 1: Introduction 🧄 Task 2: Technical Background 🧅 Task 3: Exploitation 🥖 Task 4: Detection https://t.co/mAFz0Ur2uz

    Post summary

    The tweet advertises a TryHackMe room that teaches how to exploit the CVE-2026-25769 vulnerability in Wazuh for remote code execution, including a practical PoC guide.

    00010140
    818 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25769 Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.0.0 through 4.14.2 have a Remote Code Execution (RCE) vulnera… https://www.cve.org/CVERecord?id=CVE-2026-25769

    Post summary

    The post announces CVE‑2026‑25769, noting that Wazuh versions 4.0.0–4.14.2 are vulnerable to remote code execution. No PoC, exploit details, or patch information is provided.

    00010150
    56.7K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-25769: CRITICAL] Wazuh 4.0.0 to 4.14.2 has a Remote Code Execution vulnerability. Upgrade to version 4.14.3 to fix. Stay secure! #cybersecurity #vulnerability #Wazuh#cve,CVE-2026-25769,#cybersecurity https://cvefind.com/CVE-2026-25769

    Post summary

    The post announces a critical RCE vulnerability in Wazuh and advises upgrading to version 4.14.3 to remediate it.

    01000135
    602 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwazuhwazuh---

Explore more