PatchSiren

Ntop CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Ntop CVE published 2026-07-02

CVE-2026-38968

CVE-2026-38968 is a critical vulnerability in ntopng, a network traffic analyzer. The vulnerability is caused by the use of weak time-seeded pseudo-randomness during session creation, which can lead to predictable session identifiers and potentially allow for session hijacking. This could enable attackers to gain unauthorized access or control over monitored network traffic. Administrators and users of nt [truncated]

HIGH Ntop CVE published 2017-01-14

CVE-2017-5473

CVE-2017-5473 is a high-severity cross-site request forgery issue in ntopng through 2.4. According to NVD, a remote attacker could hijack the authentication of arbitrary users by inducing authenticated requests against administrative endpoints such as add-user, preference changes, user deletion, and password reset. The issue was publicly disclosed on 2017-01-14 and later marked modified by NVD on 2026-05-13.