VORANT. Threat Intelligence Sign in Get the full feed

Elastic patches 11 CVEs across Stack products

medium vulnerability

Elastic released security updates for multiple vulnerabilities in Elasticsearch, Kibana, Fleet Server, and Elastic Defend that could lead to data integrity/confidentiality issues and DoS.

The French CERT (CERT-FR) issued an advisory on July 1, 2026 regarding multiple security vulnerabilities discovered across Elastic's product line. The affected products include Elastic Defend versions 8.6.x through 9.3.x, Elasticsearch versions 7.x through 9.4.x, Fleet Server versions 8.x and 9.x, and Kibana versions 7.x through 9.4.x. The vulnerabilities enable various attack vectors including remote denial of service, confidentiality breaches, integrity violations, and security policy bypass.

Elastic has released patches addressing 11 distinct CVEs (CVE-2026-32283, CVE-2026-49087 through CVE-2026-49091, and CVE-2026-56148 through CVE-2026-56152) through a coordinated security update across all affected products. The vendor published 11 separate security bulletins (ESA-2026-41 through ESA-2026-53) detailing the fixes and affected version ranges.

Organizations running Elastic Stack components should prioritize patching to the latest versions: Elasticsearch 7.17.24/8.19.17/9.3.5/9.4.3+, Kibana 7.17.15/8.16.3+/8.17.2+/8.18.9+/8.19.17+/9.0.8+/9.1.6+/9.3.6+/9.4.3+, Fleet Server 8.19.15/9.3.4+, and Elastic Defend 8.19.13/9.2.7/9.3.2+. Given the widespread deployment of Elastic Stack in enterprise environments for logging, monitoring, and security operations, administrators should review the vendor bulletins and plan updates accordingly.

Mentioned in this report

Vulnerabilities CVE-2026-32283CVE-2026-49087CVE-2026-49088CVE-2026-49089CVE-2026-49090CVE-2026-49091CVE-2026-56148CVE-2026-56149CVE-2026-56150CVE-2026-56151CVE-2026-56152

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0826

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free