ZoomEye finds 14,061 exposed Graylog servers on the internet
A ZoomEye scan on September 28, 2026 found 14,061 assets matching the Graylog signature. Log aggregation platforms concentrate authentication events, errors and network data, so an exposed instance can leak or allow tampering with the audit record.
- ZoomEye: 14,061 matches for app="Graylog" as of September 28, 2026
- An unauthenticated Graylog instance exposes log search and admin actions
- Risk depends on config: interface binding, default admin password, API auth
- Unauthenticated log ingestion lets anyone pollute the record
Read next
Security