Blog Entries

01. 10. 2026 Damiano Chini Bug Fixes, NetEye

NetEye 4 – Security Advisory (Grafana)

Important: Grafana security update Type/Severity NetEye Product Security has rated this update as having a medium security impact. Topic An update for the grafana packages is now available for NetEye 4. Security Fix for NetEye 4.49 and 4.50 Summary Four medium-severity CVEs were fixed (CVSS 4.3–5.4). Three concern permission scoping: alert rules listable from folders a user may…

Read More
21. 09. 2026 Cecilia Marchi Bug Fixes, NetEye

NetEye 4 – Security Advisory (GLPI)

Important: GLPI security update Type/Severity NetEye Product Security has rated this update as having a high security impact. Topic An update for the glpi packages is now available for NetEye 4. Security Fix for NetEye 4.49 Summary This is the list of vulnerabilities patched in this update: For details on how to apply this update, which includes the…

Read More
21. 09. 2026 Luca Tecchio Bug Fixes, NetEye

NetEye 4 – Security Advisory (Keycloak)

Important: Keycloak security update Type/Severity NetEye Product Security has rated this update as having a high security impact. Topic An update for the keycloak packages is now available for NetEye 4. Security Fix for NetEye 4.49: Summary This Keycloak update (version 26.7.4) resolves several security issues identified in upstream Keycloak: For details on how to apply this…

Read More
17. 09. 2026 Patrick Harasser Bug Fixes, NetEye

NetEye 4 – Security Advisory (Grafana)

Important: Grafana security update Type/Severity NetEye Product Security has rated this update as having a high security impact. Topic An update for the grafana packages is now available for NetEye 4. Security Fix for NetEye 4.49 Summary An authenticated user with permission to create or edit alert rules can bypass datasource query authorization by marking an alert rule…

Read More
09. 09. 2026 Davide Zeni Bug Fixes, NetEye

NetEye 4 – Security Advisory (Keycloak)

Important: Keycloak security update Type/Severity NetEye Product Security has rated this update as having a high security impact. Topic An update for the keycloak packages is now available for NetEye 4. Security Fix for NetEye 4.49 Summary This Keycloak update (version 26.7.3) fixes 20 security issues found during internal review. None of them are rated Critical for running…

Read More
03. 09. 2026 Patrick Harasser Bug Fixes, NetEye

NetEye 4 – Security Advisory (Elastic Stack)

Important: Elastic Stack security update Type/Severity NetEye Product Security has rated this update as having a High security impact. Topic Updates for the Elastic Stack packages are now available for NetEye 4. Security Fix for NetEye 4.49 CVEs Elastic Agent Kibana Most of the 11 CVEs are authorization and access control weaknesses affecting Kibana, including…

Read More
26. 08. 2026 Davide Zeni Bug Fixes, NetEye

NetEye 4 – Security Advisory (Keycloak)

Important: Keycloak security update Type/Severity NetEye Product Security has rated this update as having a critical security impact. Topic An update for the keycloak packages is now available for NetEye 4. Security Fix for NetEye 4.49 Summary This vulnerability, tracked as CVE-2026-18963 (CVSS 9.1, Critical), affects the reset-credentials authentication flow in Keycloak. Due to improper state validation, an…

Read More
20. 08. 2026 Patrick Harasser Bug Fixes, NetEye

NetEye 4.49 – Security Advisory (Icinga 2)

Important: Icinga 2 security update Type/Severity NetEye Product Security has rated this update as having a medium security impact. Topic An update for the icinga package is now available for NetEye 4. Security Fix for NetEye 4.49 Summary This release fixes authorization bypasses in /v1/events filter expressions and a node-to-node memory-exhaustion DoS, while also preventing sensitive data from…

Read More
14. 08. 2026 Patrick Harasser Bug Fixes, NetEye

NetEye 4 – Security Advisory (Elastic Stack)

Important: Elastic Stack security update Type/Severity NetEye Product Security has rated this update as having a High security impact. Topic Updates for the Elastic Stack packages are now available for NetEye 4. Security Fix for NetEye 4.49 CVEs Elasticsearch Fleet Server Kibana Most of the 36 CVEs are Denial of Service vulnerabilities affecting Elasticsearch (uncontrolled…

Read More
28. 07. 2026 Patrick Harasser Bug Fixes, NetEye

NetEye 4.46 – Security Advisory (Icinga 2)

Important: Icinga 2 security update Type/Severity NetEye Product Security has rated this update as having a critical security impact. Topic An update for the icinga package is now available for NetEye 4. Security Fix for NetEye 4.46 Summary The vulnerabilities include an authentication bypass leading to privilege escalation via trusted CA impersonation, a stack-based buffer overflow, and an…

Read More
28. 07. 2026 Patrick Harasser Bug Fixes, NetEye

NetEye 4.47 – Security Advisory (Icinga 2)

Important: Icinga 2 security update Type/Severity NetEye Product Security has rated this update as having a critical security impact. Topic An update for the icinga package is now available for NetEye 4. Security Fix for NetEye 4.47 Summary The vulnerabilities include an authentication bypass leading to privilege escalation via trusted CA impersonation, a stack-based buffer overflow, and an…

Read More
28. 07. 2026 Cecilia Marchi Bug Fixes, NetEye

NetEye 4 – Security Advisory (NagVis)

Important: NagVis security update Type/Severity NetEye Product Security has rated this update as having a high security impact. Topic An update for the nagvis and icingaweb2-module-nagvis packages is now available for NetEye 4. Security Fix for NetEye 4.48 Summary The vulnerabilities include two livestatus injections in dynmaps and a XSS via WYSIWYG editor. For details on how to…

Read More
24. 07. 2026 Gabriele Bocchi Bug Fixes, NetEye

NetEye 4 – Security Advisory (Elastic Stack)

Important: Elastic Stack security update Type/Severity NetEye Product Security has rated this update as having a Medium security impact. Topic Updates for the Elastic Stack packages are now available for NetEye 4. Security Fix for NetEye 4.48 CVEs Elasticsearch Kibana Most of the 15 CVEs are Denial of Service vulnerabilities affecting Elasticsearch (ES|QL, EQL, search-query parsing) and Kibana…

Read More
07. 07. 2026 Patrick Harasser Bug Fixes, NetEye

NetEye 4.48 – Security Advisory (Icinga 2)

Important: Icinga 2 security update Type/Severity NetEye Product Security has rated this update as having a critical security impact. Topic An update for the icinga package is now available for NetEye 4. Security Fix for NetEye 4.48 Summary The vulnerabilities include an authentication bypass leading to privilege escalation via trusted CA impersonation, a stack-based buffer overflow, and an…

Read More
07. 07. 2026 Gabriele Bocchi Bug Fixes, NetEye

NetEye 4 – Security Advisory (Elastic Stack)

Important: Elastic Stack security update Type/Severity NetEye Product Security has rated this update as having a Medium security impact. Topic An update for the Kibana package is now available for NetEye 4. Security Fix for NetEye 4.48 CVEs All of the 3 CVEs are Denial of Service vulnerabilities that affect Kibana, within the Elastic Stack. Affected Products All…

Read More

Archive