CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

[UPDATE] [high] Cacti: Multiple Vulnerabilities

highpublic exploitCVE-2026-1513CVE-2026-22802CVE-2026-32935CVE-2026-39893CVE-2026-39894CVE-2026-39895
An attacker can exploit multiple vulnerabilities in Cacti to execute arbitrary code, bypass security measures, conduct a cross-site scripting attack, conduct a SQL injection attack, manipulate files, and disclose information.

CSIRTS triage

What
Multiple vulnerabilities enable arbitrary code execution, security bypass, cross-site scripting, SQL injection, file manipulation, and information disclosure.
Who is affected
Cacti deployments running vulnerable versions.
Urgency
High; multiple severe vulnerability classes present.
Action
Update Cacti to a patched version addressing CVE-2026-1513, CVE-2026-22802, and related CVEs.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Cacti

Get an email when a new Cacti advisory drops — max one per day, one-click unsubscribe.

Details

Source
CERT-Bund (BSI) Security Advisories (DE · national-cert · site)
Severity
high
Published
2026-08-12
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1931

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-1513coverage & exploitation statusNVD · CVE.org
CVE-2026-22802coverage & exploitation statusNVD · CVE.org
CVE-2026-32935coverage & exploitation statusNVD · CVE.org
CVE-2026-39893coverage & exploitation statusNVD · CVE.org
CVE-2026-39894coverage & exploitation statusNVD · CVE.org
CVE-2026-39895coverage & exploitation statusNVD · CVE.org
CVE-2026-39896coverage & exploitation statusNVD · CVE.org
CVE-2026-39897coverage & exploitation statusNVD · CVE.org
CVE-2026-39898coverage & exploitation statusNVD · CVE.org
CVE-2026-39899coverage & exploitation statusNVD · CVE.org
CVE-2026-39900coverage & exploitation statusNVD · CVE.org
CVE-2026-39902coverage & exploitation statusNVD · CVE.org
CVE-2026-39938coverage & exploitation statusNVD · CVE.org
CVE-2026-39939coverage & exploitation statusNVD · CVE.org
CVE-2026-39947coverage & exploitation statusNVD · CVE.org
CVE-2026-39948coverage & exploitation statusNVD · CVE.org
CVE-2026-39949coverage & exploitation statusNVD · CVE.org
CVE-2026-39950coverage & exploitation statusNVD · CVE.org
CVE-2026-39951coverage & exploitation statusNVD · CVE.org
CVE-2026-39952coverage & exploitation statusNVD · CVE.org
CVE-2026-39955coverage & exploitation statusNVD · CVE.org
CVE-2026-40078coverage & exploitation statusNVD · CVE.org
CVE-2026-40079coverage & exploitation statusNVD · CVE.org
CVE-2026-40080coverage & exploitation statusNVD · CVE.org
CVE-2026-40081coverage & exploitation statusNVD · CVE.org
CVE-2026-40082coverage & exploitation statusNVD · CVE.org
CVE-2026-40083coverage & exploitation statusNVD · CVE.org
CVE-2026-40084coverage & exploitation statusNVD · CVE.org
CVE-2026-40194coverage & exploitation statusNVD · CVE.org
CVE-2026-40941coverage & exploitation statusNVD · CVE.org
CVE-2026-41884coverage & exploitation statusNVD · CVE.org
CVE-2026-44481coverage & exploitation statusNVD · CVE.org
CVE-2026-46531coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for Cacti

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from CERT-Bund (BSI) Security Advisories