CVE-2026-39938Disclosure(cacti / cacti)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch cacti cacti systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have unauthenticated LFI through graph_theme and rrdtool IPC serialization hardening. This issue has been resolved in version 1.2.31.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-78

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cacti

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 6 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • Peaked 3d ago at 3 mentions (2026-06-30); latest day: 1
  • 8 total mentions across 6 days

Affected systems

Vendors
Products
cacti

Deep dive

Activity timeline8 mentions / 6d
01223Mentions · 2026-06-25: 1Mentions · 2026-06-27: 1Mentions · 2026-06-30: 3Mentions · 2026-07-01: 1Mentions · 2026-07-02: 1Mentions · 2026-07-07: 1PoC Mentioned / Linked · 2026-06-27: 1Active Exploitation · 2026-06-27: 1Patch / Workaround · 2026-06-30: 2Patch / Workaround · 2026-07-02: 1Technical Details · 2026-06-25: 1Technical Details · 2026-06-27: 1Technical Details · 2026-06-30: 3Technical Details · 2026-07-01: 106-2506-2706-3007-0107-0207-07
Signal classification3 categories
Disclosure
562.5%
Patch
225.0%
Active Exploitation
112.5%
Referenced assets13 URLs
Classification over time
DateTotalLabels
2026-06-251
Disclosure1
2026-06-271
Active Exploitation1
2026-06-303
Disclosure2Patch1
2026-07-011
Disclosure1
2026-07-021
Patch1
2026-07-071
Disclosure1
Full discourse8 posts
  • FOFA@fofabot
    Disclosure

    ⚠️⚠️ CVE-2026-39893 (CVSS 9.8) + CVE-2026-39948 (CVSS 9.8) + CVE-2026-39955 (CVSS 9.8) + CVE-2026-39938 (CVSS 9.8): Pre-auth SQLi and LFI in Cacti <=1.2.30 via graph_view.php; guest graph viewing can expose unauthenticated paths. 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJDYWN0aS1Nb25pdG9yaW5nIg== 🎯16.8K+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="Cacti-Monitoring" 🔖Refer: https://securityonline.info/cacti-vulnerabilities-1-2-31/ #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    The tweet announces four high‑severity vulnerabilities (CVE‑2026‑39893, CVE‑2026‑39948, CVE‑2026‑39955, CVE‑2026‑39938) in Cacti ≤ 1.2.30, highlighting pre‑authentication SQLi and LFI issues; it provides FOFA search links and a reference page for further details.

    4270954014.7K
    14.7K followersView on X
  • Hunter@HunterMapping
    Disclosure

    🚨Alert🚨 CVE-2026-39893 (CVSS 9.8) & CVE-2026-39955 (CVSS 9.8) & CVE-2026-39938 (CVSS 9.8): Critical Pre-Authentication SQL Injection Vulnerabilities in Cacti. 📊19.4K+ Services are found on the http://hunter.how yearly. 🔗Hunter Link:https://hunter.how/list?searchValue=product.name%3D%22Cacti%22 👇Query HUNTER : http://product.name="Cacti" 📰Refer:https://github.com/Cacti/cacti/security/advisories/GHSA-69gg-mjfm-jjpc https://cyberpress.org/critical-cacti-vulnerabilities/ #hunterhow #infosec #infosecurity #OSINT #Vulnerability

    Post summary

    The post announces three high‑CVSS SQL injection flaws in Cacti, citing their CVEs and linking to advisories and an external service scan, but it provides no exploitation proof or remediation guidance.

    18045195.5K
    26.0K followersView on X
  • ExploitGrid@exploitgrid
    Active Exploitation

    Top CVEs w/ public exploits (Jun 20–27): CVE-2026-48908 Joomla SPB RCE (exploited live) CVE-2026-48909 Joomla SP LMS PHP Obj injection CVE-2026-12417 SignUp/In admin takeover CVE-2026-12416 Invoice Generator takeover CVE-2026-39938 Cacti LFI Protect via http://exploitgrid.net

    Post summary

    The post enumerates CVEs with publicly available exploits, confirms at least one is actively used in the wild, and provides basic technical details but no patches or debunking.

    2502191.9K
    33 followersView on X
  • Daily CyberSecurity@the_yellow_fall
    Patch

    Cacti vulnerabilities in 1.2.30 include pre-auth SQL injection and LFI, both CVSS 9.8 (CVE-2026-39955, CVE-2026-39938). Update to 1.2.31 now. #Cacti #SQLInjection #LFI #CVE #Cybersecurity #Infosec https://securityonline.info/cacti-vulnerabilities-1-2-31 https://t.co/RyOPac2ICl

    Post summary

    The tweet warns of critical pre-auth SQL injection and LFI flaws in Cacti 1.2.30 and recommends applying the 1.2.31 update.

    02073893
    12.9K followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Cacti ❗ CVE-2026-39955 ❗ CVE-2026-39938 ❗ CVE-2026-39893 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-cacti/ https://t.co/FpwhCvIjS8

    Post summary

    The post announces three new CVE vulnerabilities affecting Cacti products and directs readers to external links for additional information.

    00000218
    6.7K followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    ネットワーク監視フレームワーク Cactiに4件の脆弱性(CVE-2026-39893・CVE-2026-39955・CVE-2026-39938・CVE-2026-39951) https://rocket-boys.co.jp/security-measures-lab/cacti-vulnerability-fix-cve-2026-39893/ #セキュリティ対策Lab #security #securitynews

    Post summary

    The post announces four CVEs affecting the Cacti monitoring framework and refers readers to a link that likely details exploits fixes, focusing on mitigation rather than exploitation.

    00000129
    454 followersView on X
  • TECHEPAGES@techepages
    Disclosure

    🚨🔧 Critical Cacti vulnerabilities expose servers to pre-auth SQL injection attacks 🔹 CVE-2026-39893 (CVSS 9.8) lets unauthenticated attackers exploit unsanitized input in graph_view.php via Cacti's guest-access feature 🔹 CVE-2026-39955 (CVSS 9.8) bypasses input validation, allowing unauthenticated SQL injection with full confidentiality/integrity/availability impact 🔹 CVE-2026-39938 (CVSS 9.8) enables unauthenticated local file inclusion via the graph_theme parameter 🔹 Admins should upgrade to Cacti 1.2.31 immediately, especially guest-accessible instances facing the two critical pre-auth flaws

    Post summary

    Three Cacti CVEs (39893, 39955, 39938) with CVSS 9.8 enable unauthenticated SQL injection and local file inclusion; users are urged to upgrade to version 1.2.31.

    0000051
    22 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-39938 Unauthenticated Local File Inclusion in Cacti 1.2.30 and Prior https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-39938

    Post summary

    The snippet announces a new unauthenticated local file inclusion vulnerability (CVE‑2026-39938) in Cacti 1.2.30 and earlier versions, directing readers to a Vulmon page for details.

    00000100
    4.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcacticacti---

Explore more