CERT-FR flags multiple LibreNMS vulnerabilities
Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.
CERT-FR warns of multiple vulnerabilities in LibreNMS before 26.9.0 enabling privilege escalation, XSS, SQL injection and data exposure.
CERT-FR issued an advisory covering multiple vulnerabilities in LibreNMS, an open-source network monitoring platform, affecting all versions prior to 26.9.0. The flaws collectively allow an attacker to achieve privilege escalation, breach data confidentiality and integrity, bypass security policies, and perform indirect remote code injection via cross-site scripting (XSS) and SQL injection (SQLi).
The advisory references five separate GitHub Security Advisories published by LibreNMS on 23 September 2026 (GHSA-2pw7-8mmj-gcw5, GHSA-9qcg-rgg9-mpjg, GHSA-cjqw-76mh-jmpv, GHSA-ffjc-4fr5-47c6, GHSA-j3qf-h24w-9f42), though no CVE identifiers or technical exploitation details are provided in the bulletin itself. No in-the-wild exploitation is mentioned.
Defenders running LibreNMS should upgrade to version 26.9.0 or later as soon as possible and consult the linked GitHub advisories for per-vulnerability technical details and patch guidance. Given LibreNMS's role as a network monitoring tool with broad visibility and often elevated access into infrastructure, organizations should prioritize patching and review authentication logs and admin-panel access for signs of privilege escalation attempts.
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1222
What this brief leaves out
This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.
It sits in a corpus of 9,789 reports from 155 sources, 1,534 of them written in the last seven days, and it grows through the day.
A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.
Create a free account What it costs