THREAT OPS › Threat News › [NVD] CVE-2026-61800 (CRITICAL 9.1) — Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.4.0 through 4.14.6, a party holding the cluster key can write, overwrite, or delete arbitrary files under /var/ossec on worker nodes, leading to re
[NVD] CVE-2026-61800 (CRITICAL 9.1) — Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.4.0 through 4.14.6, a party holding the cluster key can write, overwrite, or delete arbitrary files under /var/ossec on worker nodes, leading to re
CVE-2026-61800 CVSS: 9.1 CRITICAL Published: 2026-08-28T02:16:21.767
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.4.0 through 4.14.6, a party holding the cluster key can write, overwrite, or delete arbitrary files under /var/ossec on worker nodes, leading to remote code execution as root. During cluster file s
Indicators of compromise
- CVE-2026-61800cve
- CVE-2026-30893cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-61800