Skip to main content

Detecting PRTG Abuse: What to Watch After CVE-2026-4637 and CVE-2026-4638

Analysis of telemetry signals for PRTG versions below 26.2.120.1449 affecting XSS and stored domain password disclosure reported in CERT-Bund WID-SEC-2026-3565.

AI-written
Inewgen
30 Sep 2026Source: Dev.to2 min read (0 views)
Share
Detecting PRTG Abuse: What to Watch After CVE-2026-4637 and CVE-2026-4638

Stock photo for illustration only, not from the actual event

Font size
  • PRTG builds prior to 26.2.120.1449 contain CVE-2026-4637 and CVE-2026-4638 vulnerabilities.
  • Successful exploitation grants admin session cookies or working domain credentials for lateral network movement.
  • ZoomEye recorded 73,811 PRTG assets as of September 25, 2026.
  • Detection relies on internal fleet telemetry rather than external search engine queries.

PRTG software deployments running builds prior to 26.2.120.1449 harbor two critical security flaws, which are formally documented in CERT-Bund advisory WID-SEC-2026-3565 and fully resolved in version 26.2.120.1449.

The first vulnerability, tracked as CVE-2026-4637, is a reflected cross-site scripting issue residing in the error page path. Triggering this flaw requires an incoming request featuring HTML within the path ending in .htm, followed by an authenticated user opening the malicious link.

cybersecurity threat analysis dashboard screen no logo

Stock photo for illustration only, not from the actual event

The second flaw, designated as CVE-2026-4638, involves the disclosure of a stored domain password through script sensor error messages. Exploiting this issue requires an account holding at least Pre-Configuration privileges to deploy an EXE or script sensor and read the resulting error feedback.

Never miss the latest news?

Subscribe to get news summaries by email - not often enough to be annoying.

โฆษณา

73,811PRTG assets on ZoomEye (Sep 2026)

A successful breach via either method yields either an administrator session cookie or a valid domain credential. Either outcome provides sufficient access for an attacker to move laterally across the entire network monitored by the PRTG instance.

From a defensive standpoint, the discrepancy where external search engines like ZoomEye return zero matches for specific CVE labels underscores a vital lesson: risk assessment cannot rely solely on external asset discovery. Security teams must audit their internal software inventory and analyze correlated telemetry directly from their active server fleet.

Individually, each detection signal appears weak. A standard Type mismatch error can stem from a genuinely broken script, while an .htm request containing angle brackets can easily originate from automated vulnerability scanners. Confidence only rises when multiple indicators correlate from the same host within a condensed timeframe.

Source: Dev.to

Comments

Leave a Comment
0/2000

Found something wrong in this article? Report an issue with this article