Most of the 36 CVEs are Denial of Service vulnerabilities affecting Elasticsearch (uncontrolled recursion in intervals queries/wildcard matching/analysis definitions, memory allocation without limits in search/highlighting) and Kibana (TSVB, connector reporting, alerting, case management, Observability log analysis, CSRF via Vega visualizations), within the Elastic Stack. The remaining CVEs relate to authorization and access control weaknesses in Kibana and Fleet Server, including Missing/Incorrect Authorization (Agent Builder privilege escalation and data tampering, Elastic Defend endpoint response actions information disclosure, cross-space access to Machine Learning trained models, unauthorized execution of Osquery/Endpoint response actions), Authorization Bypass Through User-Controlled Key (Fleet Elastic Agent API key disclosure, cross-space alerting telemetry and ML disclosure), Code Injection in Fleet Server, and an Out-of-range Pointer Offset in the Elasticsearch Machine Learning native inference process, that can lead to unauthorized information disclosure, privilege escalation, data tampering or remote code execution.
Important: Keycloak security update Type/Severity NetEye Product Security has rated this update as having a high security impact. Topic An update for the keycloak packages is now available for NetEye 4. Security Fix for NetEye 4.49 26.7.3_neteye1.46.1-1 Summary This Keycloak update (version 26.7.3) Read More
Icinga 2 live-creation requests are no longer lost during reload During a Director deployment, Icinga 2 reloads its configuration in the background. Previously, live-creation requests could still be processed for a short time after a reload had been requested. This Read More
Important: Elastic Stack security update Type/Severity NetEye Product Security has rated this update as having a High security impact. Topic Updates for the Elastic Stack packages are now available for NetEye 4. Security Fix for NetEye 4.49 9.4.6_neteye3.103.8-1 CVEs Elastic Read More
Historical log data is valuable—until the cost of keeping every shard online starts competing with the value of the data itself. Elasticsearch searchable snapshots offer a practical middle ground for a NetEye installation: keep an index in a snapshot repository, Read More
Important: Keycloak security update Type/Severity NetEye Product Security has rated this update as having a critical security impact. Topic An update for the keycloak packages is now available for NetEye 4. Security Fix for NetEye 4.49 26.7.2_neteye1.46.1-1 Summary This vulnerability, tracked as CVE-2026-18963 Read More