Grafana security advisory (AV26-860)
Serial Number: AV26-860 Date: August 28, 2026 As of August 27, 2026, Grafana is affected by a vulnerability in the following product: Alloy Prior to or equal to 1.18.1 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Grafana: The open and composable observability platform | Grafana Labs CVE-2026-19516 CVE Record
CSIRTS triage
- What
- Unspecified vulnerability in Grafana Alloy observability platform.
- Who is affected
- Grafana Alloy deployments running version 1.18.1 or earlier.
- Urgency
- Medium; specific vulnerability type and severity are not detailed in the advisory.
- Action
- Update Grafana Alloy to the latest version after 1.18.1.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Alloy
Get an email when a new Alloy advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/grafana-security-advisory-av26-860
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-758890.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-195160.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-75889 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-19516 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
More from Canadian Centre for Cyber Security
- unknownMikrotik security advisory (AV26-887) – Update 12026-09-11
- criticalAL26-020 - Vulnerabilities Impacting MikroTik RouterOS - CVE-2026-67276, CVE-2026-67277 and CVE-2026-860602026-09-10
- unknownHPE security advisory (AV26-909)2026-09-10
- unknownWebPros security advisory (AV26-908)2026-09-10
- unknownAdobe security advisory (AV26-808) – Update 12026-09-10