Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-17548: CWE-862: Missing Authorization in Checkmk GmbH CheckmkCVE-2026-17548
0

Missing authorization in Checkmk <2.5.0p12, <2.4.0p36, <2.3.0p50 and all 2.2.0 versions allows an authenticated user who knows the ID of a background job to view that job's status and results.

Join the discussion
Improper authentication in the agent receiver of Checkmk <2.5.0p10 allows an unauthenticated remote attacker to bypass mutual TLS client certificate… (CVE-2026-15576)CVE-2026-15576
0

Checkmk versions prior to 2.5.0p10 contain an improper authentication vulnerability in the agent receiver component. This flaw allows an unauthenticated remote attacker to bypass mutual TLS client certificate verification for relay endpoints by using a fixed placeholder identity in the request URL. The vulnerability affects only the Cloud, Ultimate, and Ultimate MT editions, as other editions do not expose relay endpoints. The impact is limited to integrity and availability. No known exploits are reported in the wild, and no official patch information is provided.

Join the discussion
CVE-2026-15576: CWE-306: Missing Authentication for Critical Function in Checkmk GmbH CheckmkCVE-2026-15576
0

Improper authentication in the agent receiver of Checkmk <2.5.0p10 allows an unauthenticated remote attacker to bypass mutual TLS client certificate verification of relay endpoints by supplying a fixed placeholder identity in the request URL, resulting in limited impact on integrity and availability. Only the Cloud, Ultimate and Ultimate MT editions are affected, as other editions do not expose relay endpoints.

Join the discussion
CVE-2026-7485: CWE-863: Incorrect Authorization in Checkmk GmbH CheckmkCVE-2026-7485
0

Incorrect authorization in frozen BI aggregations in Checkmk <2.5.0p2, <2.4.0p29, <2.3.0p47, and all 2.2.0 versions allows an authenticated user with restricted host and service visibility to learn the names and the existence of hosts and services they are not authorized to see.

Join the discussion
CVE-2026-15227: CWE-862: Missing Authorization in Checkmk GmbH CheckmkCVE-2026-15227
0

CVE-2026-15227 is a medium severity vulnerability in Checkmk that allows an authenticated user without the 'Edit foreign Reports' permission to modify reports owned by other users. It affects Checkmk versions prior to 2.5.0p10, 2.4.0p35, and 2.3.0p49, as well as version 2.2.0 which is end-of-life. This is due to missing authorization checks in the affected versions.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Package: pkg:github/checkmk/checkmk
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses