Kibana is a web-based visualization and exploration frontend for Elasticsearch, forming part of the Elastic Stack.
Kibana is a web-based visualization and exploration frontend for Elasticsearch, forming part of the Elastic Stack. Recent reports describe vulnerabilities in Kibana that enable server-side request forgery (SSRF) and cross-site scripting (XSS), potentially allowing attackers to reach internal resources or inject/script within a Kibana session. Its widespread use for data analytics and monitoring makes unpatched Kibana deployments a notable cybersecurity risk, especially if exposed to untrusted networks.
CVE-2026-4020 is an information disclosure vulnerability in the Gravity SMTP WordPress plugin, published on March 31, 2026. The flaw allows unauthenticated visitors to access sensitive system reports, including SMTP…
Cybersecurity researchers from Huntress have uncovered a campaign where a threat actor exploited multiple software vulnerabilities, including the SolarWinds Web Help Desk, to exfiltrate data to a free trial instance of…
Multiple vulnerabilities in Kibana have been identified, allowing attackers to execute Server-Side Request Forgery (SSRF) and Cross-Site Scripting (XSS) attacks. These vulnerabilities could potentially expose sensitive…
Elastic has released critical security updates to address four significant vulnerabilities in its software stack. These vulnerabilities include a high-severity flaw that allows arbitrary file disclosure and could lead…
CyberSentinel AI has released version 3.0 of its open-source cybersecurity platform, integrating 33 penetration testing and threat intelligence tools. The platform features a provider-agnostic AI engine that supports…
On February 27, 2026, a security incident was identified involving a single IP address that initially requested a login page. This IP later appended ?debug=true across multiple hosts, indicating probing behavior by an…
Multiple vulnerabilities in Kibana have been identified, allowing attackers to execute Server-Side Request Forgery (SSRF) and Cross-Site Scripting (XSS) attacks. These vulnerabilities potentially expose systems to…