PRTG flaws CVE-2026-4637 and CVE-2026-4638 patched in 26.2.120.1449
PRTG Network Monitor builds before 26.2.120.1449 carry a reflected XSS in the error page path (CVE-2026-4637) and disclosure of a stored domain password via a script sensor error message (CVE-2026-4638). Exploitation yields an administrator session cookie or working domain credentials, enabling lateral movement. The fix shipped on June 3, 2026; ZoomEye lists 73,811 PRTG assets.
- CVE-2026-4637: reflected XSS via .htm path, requires a signed-in user to open a link
- CVE-2026-4638: domain password leaked through an EXE/Script sensor error
- Fixed in PRTG 26.2.120.1449, released June 3, 2026
- ZoomEye: 73,811 PRTG assets; risk is defined by build, not a search label
Read next
Security