Loading HuntDB...

Wazuh Server Deserialization of Untrusted Data Vulnerability

Added June 10, 2025 Due July 1, 2025 CVE-2025-24016
On Track Wazuh / Wazuh Server CWE-502

Description

Wazuh contains a deserialization of untrusted data vulnerability that allows for remote code execution on Wazuh servers.

Required Action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

References

Additional Information

Catalog Version
2025.06.10
Catalog Released
June 10, 2025
Days Until Due
17 days
Last Updated
3 days, 16 hours ago