Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

wazuh

About This Vendor

wazuh is a technology vendor producing software and infrastructure products. As a software provider, wazuh's broad product portfolio across multiple domains—including operating systems, cloud infrastructure, enterprise applications, databases, networking, and security tools—creates a large attack surface. Additionally, long support cycles, widespread deployment, and continuous feature development contribute to the accumulation of discovered vulnerabilities over time. Major vendors typically report higher CVE counts not necessarily due to inferior security, but because of greater exposure to security research, responsible disclosure practices, and the sheer complexity of maintaining multiple product lines and legacy systems. Regular security assessments and patching of wazuh's products are critical for organizations running their software in production environments.

Vulnerability Trends for This Vendor

SecUtils has indexed 71 known vulnerabilities from wazuh. This includes 10 critical-severity issues and 25 high-severity issues that represent significant risk. These vulnerabilities affect 5 distinct products across wazuh's portfolio, demonstrating the breadth of the vendor's product ecosystem and the importance of comprehensive patch management strategies. Disclosure dates span from 2018 through 2026, reflecting sustained security scrutiny over multiple years. Organizations deploying wazuh products should maintain active vulnerability monitoring, prioritize critical patches, and implement compensating controls where patches cannot be applied immediately.

ID Date Published Last Modified Severity (CVSSv3) Severity (CVSSv2) Exploit Available
CVE-2018-19666 2018-11-29 2026-06-17 7.8 7.2 Unknown
CVE-2021-26814 2021-03-06 2026-06-17 8.8 6.5 Likely
CVE-2021-41821 2021-09-29 2026-06-17 6.5 4.0 Likely
CVE-2021-44079 2021-11-22 2026-06-17 9.8 7.5 Likely
CVE-2022-40497 2022-09-28 2026-06-17 8.8 - -
CVE-2023-42455 2023-10-09 2026-06-17 8.8 - -
CVE-2023-42463 2024-01-12 2026-06-17 7.4 - -
CVE-2023-49275 2024-04-19 2026-06-17 6.5 - -
CVE-2023-50260 2024-04-19 2026-06-17 8.8 - -
CVE-2024-32038 2024-04-19 2026-06-17 9.8 - -
CVE-2024-35177 2025-02-03 2026-06-17 7.8 - -
CVE-2024-47770 2025-02-03 2026-06-17 4.6 - -
CVE-2025-24016 2025-02-10 2026-06-17 9.9 - -
CVE-2024-1243 2025-06-11 2026-06-17 7.2 - -
CVE-2025-59938 2025-09-27 2026-06-17 6.5 - -
CVE-2025-62785 2025-10-29 2026-06-17 7.5 - -
CVE-2025-62786 2025-10-29 2026-06-17 8.1 - -
CVE-2025-62787 2025-10-29 2026-06-17 7.5 - -
CVE-2025-62788 2025-10-29 2026-06-17 7.5 - -
CVE-2025-62789 2025-10-29 2026-06-17 7.5 - -
CVE-2025-62790 2025-10-29 2026-06-17 7.5 - -
CVE-2025-62791 2025-10-29 2026-06-17 7.5 - -
CVE-2025-62792 2025-10-29 2026-06-17 7.5 - -
CVE-2025-30201 2025-11-21 2026-06-17 7.7 - -
CVE-2025-54866 2025-11-21 2026-06-17 5.5 - -
CVE-2025-64169 2025-11-21 2026-06-17 4.9 - -
CVE-2026-25769 2026-03-17 2026-06-17 9.1 - -
CVE-2026-25770 2026-03-17 2026-06-17 9.1 - -
CVE-2026-25771 2026-03-17 2026-06-17 5.3 - -
CVE-2026-25772 2026-03-17 2026-06-17 4.9 - -
CVE-2026-25790 2026-03-17 2026-06-17 4.9 - -
CVE-2023-7340 2026-03-27 2026-06-17 3.5 - -
CVE-2026-32983 2026-03-27 2026-06-17 5.8 - -
CVE-2026-32984 2026-03-27 2026-06-17 3.5 - -
CVE-2025-15615 2026-03-27 2026-06-17 5.8 - -
CVE-2025-15616 2026-03-27 2026-06-17 6.7 - -
CVE-2025-15617 2026-03-27 2026-06-17 6.5 - -
CVE-2025-15612 2026-03-27 2026-06-17 4.8 - -
CVE-2026-26204 2026-04-29 2026-06-17 4.4 - -
CVE-2026-26206 2026-04-29 2026-06-17 6.5 - -
CVE-2026-28221 2026-04-29 2026-06-17 6.5 - -
CVE-2026-30893 2026-04-29 2026-06-17 9.0 - -
CVE-2026-41499 2026-04-29 2026-06-17 6.5 - -
CVE-2026-33434 2026-07-17 2026-07-20 4.3 - -
CVE-2026-33754 2026-07-17 2026-07-20 6.5 - -
CVE-2026-34150 2026-07-17 2026-07-20 7.5 - -
CVE-2026-39359 2026-07-17 2026-07-20 7.5 - -
CVE-2026-40106 2026-07-17 2026-07-20 4.7 - -
CVE-2026-44251 2026-07-17 2026-07-20 6.5 - -
CVE-2026-28220 2026-07-20 2026-07-29 8.4 - -
CVE-2026-67307 2026-08-01 2026-09-01 6.3 - -
CVE-2026-67308 2026-08-01 2026-09-09 - - -
CVE-2026-44252 2026-08-19 2026-09-09 - - -
CVE-2026-44253 2026-08-19 2026-09-09 4.9 - -
CVE-2026-44254 2026-08-19 2026-09-09 5.3 - -
CVE-2026-46343 2026-08-19 2026-09-09 - - -
CVE-2026-41424 2026-08-19 2026-09-09 8.2 - -
CVE-2026-44255 2026-08-19 2026-09-09 5.3 - -
CVE-2026-44256 2026-08-19 2026-09-09 5.3 - -
CVE-2026-44901 2026-08-19 2026-09-15 8.4 - -
CVE-2026-45798 2026-08-19 2026-09-15 7.5 - -
CVE-2026-48024 2026-08-19 2026-09-15 9.1 - -
CVE-2026-48162 2026-08-19 2026-09-15 9.1 - -
CVE-2026-49392 2026-08-19 2026-09-15 5.3 - -
CVE-2026-49441 2026-08-19 2026-09-15 9.1 - -
CVE-2026-54083 2026-08-28 2026-09-15 8.1 - -
CVE-2026-54084 2026-08-28 2026-09-15 5.3 - -
CVE-2026-54085 2026-08-28 2026-09-15 7.1 - -
CVE-2026-61783 2026-08-28 2026-09-15 6.5 - -
CVE-2026-61800 2026-08-28 2026-09-15 9.1 - -
CVE-2026-61802 2026-08-28 2026-09-15 6.5 - -

How SecUtils Normalizes Vendor Data

SecUtils aggregates National Vulnerability Database (NVD) and MITRE records for wazuh by normalizing vendor identifiers across diverse data sources, mapping vendor names to their associated product lines, and collecting all known vulnerabilities under a unified vendor context. For every CVE associated with wazuh's products, we extract and structure Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) categories, CVSS severity metrics, and reference links to enable rapid vulnerability identification and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and vendor vulnerability tracking.