CVE-2026-38968 is a critical vulnerability in ntopng, a network traffic analyzer. The vulnerability is caused by the use of weak time-seeded pseudo-randomness during session creation, which can lead to predictable session identifiers and potentially allow for session hijacking. This could enable attackers to gain unauthorized access or control over monitored network traffic. Administrators and users of nt [truncated]
CVE-2017-5473 is a high-severity cross-site request forgery issue in ntopng through 2.4. According to NVD, a remote attacker could hijack the authentication of arbitrary users by inducing authenticated requests against administrative endpoints such as add-user, preference changes, user deletion, and password reset. The issue was publicly disclosed on 2017-01-14 and later marked modified by NVD on 2026-05-13.