chiprook
← Security
SecuritySeptember 30, 2026, 12:00

PRTG flaws CVE-2026-4637 and CVE-2026-4638 patched in 26.2.120.1449

PRTG Network Monitor builds before 26.2.120.1449 carry a reflected XSS in the error page path (CVE-2026-4637) and disclosure of a stored domain password via a script sensor error message (CVE-2026-4638). Exploitation yields an administrator session cookie or working domain credentials, enabling lateral movement. The fix shipped on June 3, 2026; ZoomEye lists 73,811 PRTG assets.

PRTG flaws CVE-2026-4637 and CVE-2026-4638 patched in 26.2.120.1449
#PRTG#Paessler
Read next
Security

Patching Guide: Closing the CVE-2026-67276 SSH Authentication Bypass on MikroTik Routers

Security

Patching Check Point VPN flaws: prioritized plan for CVE-2026-85102 and CVE-2026-85103

Security

Cisco Patches Actively Exploited Email Gateway Zero-Day (CVE-2026-76461)

Security

JumpServer patches QVD-2026-65008 AccessKey disclosure flaw