CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-71287

highCVSS 8.8covered by 2 sourcesfirst seen 2026-08-05
A remote, authenticated attacker can exploit a vulnerability in Cacti to conduct a SQL injection attack.

CSIRTS triage

What
SQL injection vulnerability in Cacti allows authenticated attackers to execute arbitrary SQL queries.
Who is affected
Cacti deployments accessible to authenticated users.
Urgency
High urgency; SQL injection can lead to data exfiltration and unauthorized database modification.
Action
Apply security patch for CVE-2026-71287 when released by Cacti project.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-71287

Get an email if CVE-2026-71287 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-71287

CVE.org record

Embed the live status

CVE-2026-71287 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-71287 status](https://www.csirts.com/badge/CVE-2026-71287)](https://www.csirts.com/cve/CVE-2026-71287)