VORANT. Threat Intelligence Sign in Get the full feed

LibreNMS Patches XSS Vulnerability

routine vulnerability technology

An XSS flaw in LibreNMS versions 25.12.0 to before 26.3.0 lets attackers inject remote code via indirect scripting.

ANSSI issued an advisory regarding a cross-site scripting (XSS) vulnerability discovered in LibreNMS, an open-source network monitoring platform. The flaw, tracked as CVE-2026-2728, affects versions from 25.12.0 up to but not including 26.3.0, and allows an attacker to perform indirect remote code injection through the web interface.

No evidence of active exploitation is mentioned in the advisory. LibreNMS has published a security advisory (GHSA-5gm9-622f-qcg5) detailing the fix, and administrators are urged to upgrade to version 26.3.0 or later to remediate the issue.

Mentioned in this report

Vulnerabilities CVE-2026-2728

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0562

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free