TL;DR

Critical RCE vulnerability in Nagios Host allows remote attackers to execute code via zabbixagent_configwizard_func after authentication, rated CVSS 7.2 by ZDI.

What happened

['Nagios Host affected', 'Remote attacker can inject commands', 'Exploits require authentication']

Why it matters for ops

['RCE impacts server security', 'CVSS rating of 7.2 indicates high risk', 'Requires immediate mitigation']

Mitigation

  • Apply patches as soon as available
  • Restrict user permissions
  • Monitor and log authentication attempts

Action items

  • Update affected components immediately
  • Review access controls

Detection IOCs

  • Unusual network traffic patterns
  • Authentication logs showing suspicious activity

Source link

http://www.zerodayinitiative.com/advisories/ZDI-26-073/