These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
The CVE-2026-67308 vulnerability exists in Wazuh workflows before version 44bf114, where a shell injection vulnerability in GitHub Actions allows attackers to execute arbitrary commands by submitting pull requests with crafted VERSION.json files. This vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. Security teams and administrators responsible for Wazuh workflows and GitHub Actions should [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-01T13:17:00.403Z and has not been modified since then. The Wazuh 5.0.0-beta1 version does not validate or override the cluster_name and cluster_node fields in inventory-sync Start FlatBuffer messages, allowing a low-privileged enrolled agent to spoof cluster attribution in indexed inventory and vuln [truncated]
CVE-2026-44251 is a remote denial of service vulnerability in Wazuh versions 3.0.0 and above, prior to 4.14.5. A size_t integer underflow in os_crypto/shared/msgs.c:389 allows any enrolled Wazuh agent to crash the wazuh-remoted process on the manager, immediately disconnecting all agents from the manager. A second code path reached by the same underflow may allow heap memory corruption. The issue has been [truncated]
A heap-based buffer overflow vulnerability exists in the syscheck component of the Wazuh agent for Windows, versions 4.6.0 and above prior to 4.14.5. The vulnerability occurs when expanding registry paths containing wildcards (* or ?). A low-privileged local attacker can force an out-of-bounds write during string concatenation, potentially leading to a Denial of Service (DoS) or Local Privilege Escalation [truncated]
A logic flaw was found in the Wazuh Manager's enrollment daemon (authd) and synchronization daemon (remoted). The authd process allows agents to select a group during enrollment but does not filter path traversal sequences. This issue has been fixed in versions 4.10.4 and 4.14.5. The vulnerability affects Wazuh Manager versions 4.0.0 through 4.10.3 and 4.11.0 through 4.14.4, and it has the potential to ex [truncated]
A heap buffer overflow vulnerability exists in Wazuh's wazuh-analysisd component, which allows an unauthenticated remote attacker to crash the Wazuh manager's analysis engine, causing a complete loss of SIEM alert processing. The vulnerability is exploitable via the default configuration shipped in the official wazuh/wazuh-docker deployment. An attacker can enroll with authd without a password to obtain a [truncated]
CVE-2026-33754 is a denial of service vulnerability in Wazuh's cluster protocol parser. A remote attacker can trigger memory exhaustion by sending a crafted message header with an arbitrarily large payload length, allowing unauthenticated denial of service of the cluster service. This issue affects Wazuh versions 3.9.0 and above, prior to 4.14.5. Users should apply the patch to prevent denial of service a [truncated]
CVE-2026-33434 is a medium-severity vulnerability in Wazuh, a free and open-source platform for threat prevention, detection, and response. The issue allows for event injection into analysisd beyond the admin-configured global rate limit due to a logic error in CheckRateLimitsMiddleware.dispatch(). Affected product deployments should be reviewed for potential exposure, and rate limit configurations should [truncated]
CVE-2026-56401 is a high-severity vulnerability in Wazuh wazuh-modulesd before 5.0.0-beta3. The vulnerability is caused by a null pointer dereference in inventory_sync FlatBuffer DataValue handling. An enrolled agent can send a verifier-valid DataValue message omitting the optional id field, causing wazuh-modulesd to crash when dereferencing data->id()->string_view() without null validation, resulting in [truncated]
A heap-buffer overflow vulnerability exists in Wazuh's authentication daemon (authd). The flaw allows remote attackers to send specially crafted input that causes memory corruption and malformed heap data. Successful exploitation results in a denial of service condition affecting availability of the authentication service. The vulnerability is rated MEDIUM severity with a CVSS score of 5.3. Affected versi [truncated]
CVE-2025-24016 is a Wazuh Server deserialization of untrusted data issue that CISA added to its Known Exploited Vulnerabilities catalog on 2025-06-10. Because it is KEV-listed, it should be treated as an active defensive priority. CISA’s guidance is to apply vendor mitigations, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.