Detecting PRTG Abuse: What to Watch After CVE-2026-4637 and CVE-2026-4638
Analysis of telemetry signals for PRTG versions below 26.2.120.1449 affecting XSS and stored domain password disclosure reported in CERT-Bund WID-SEC-2026-3565.

Stock photo for illustration only, not from the actual event
- PRTG builds prior to 26.2.120.1449 contain CVE-2026-4637 and CVE-2026-4638 vulnerabilities.
- Successful exploitation grants admin session cookies or working domain credentials for lateral network movement.
- ZoomEye recorded 73,811 PRTG assets as of September 25, 2026.
- Detection relies on internal fleet telemetry rather than external search engine queries.
PRTG software deployments running builds prior to 26.2.120.1449 harbor two critical security flaws, which are formally documented in CERT-Bund advisory WID-SEC-2026-3565 and fully resolved in version 26.2.120.1449.
The first vulnerability, tracked as CVE-2026-4637, is a reflected cross-site scripting issue residing in the error page path. Triggering this flaw requires an incoming request featuring HTML within the path ending in .htm, followed by an authenticated user opening the malicious link.

Stock photo for illustration only, not from the actual event
The second flaw, designated as CVE-2026-4638, involves the disclosure of a stored domain password through script sensor error messages. Exploiting this issue requires an account holding at least Pre-Configuration privileges to deploy an EXE or script sensor and read the resulting error feedback.
A successful breach via either method yields either an administrator session cookie or a valid domain credential. Either outcome provides sufficient access for an attacker to move laterally across the entire network monitored by the PRTG instance.
From a defensive standpoint, the discrepancy where external search engines like ZoomEye return zero matches for specific CVE labels underscores a vital lesson: risk assessment cannot rely solely on external asset discovery. Security teams must audit their internal software inventory and analyze correlated telemetry directly from their active server fleet.
Individually, each detection signal appears weak. A standard Type mismatch error can stem from a genuinely broken script, while an .htm request containing angle brackets can easily originate from automated vulnerability scanners. Confidence only rises when multiple indicators correlate from the same host within a condensed timeframe.
Source: Dev.to
Found something wrong in this article? Report an issue with this article
Comments
Leave a Comment