LIVE · cybersecurity feed
Live wire
vendor

Elastic

23 CVEs published in the last four months and 5 stories. Exploited flaws first.

Critical0
High20
Medium3
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-726498.8highelasticsearchDeserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote cod4d ago
CVE-2026-726428.8highelasticsearchThe native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model 23d ago
CVE-2026-631378.3highkibanaIncorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Exploiting Incorrectly Configured4d ago
CVE-2026-726658.1highkibanaMissing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic Defend respons23d ago
CVE-2026-490918highkibanaImproper Output Neutralization for Logs (CWE-117) in Kibana can lead to log injection via Log Injection-Tampering-66d ago
CVE-2026-786047.8highelastic agentIncorrect Permission Assignment for Critical Resource (CWE-732) in Elastic Agent can lead to local privilege escal3d ago
CVE-2026-726727.7highkibanaThe Elastic Security capability that suggests existing field values while a user authors endpoint policy artifacts23d ago
CVE-2026-423987.7highkibanaServer-Side Request Forgery (CWE-918) in Kibana allows authenticated users with connector management privileges to100d ago
CVE-2026-726707.7highkibanaA lower privileged user who holds only the privilege to read agent policies can read the entire configuration of a23d ago
CVE-2026-726697.6highkibanaThe state that Kibana stores for an Observability Onboarding flow is not bound to the user who created the flow, a23d ago
CVE-2026-726587.3highkibanaCross-Site Request Forgery (CWE-352) in Kibana can lead to privilege escalation via Cross Site Request Forgery (CA23d ago
CVE-2026-726777.3highkibanaRelative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative 23d ago
CVE-2026-785927.3highkibanaImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Kibana can lead to the 4d ago
CVE-2026-785907.3highkibanaImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet featur3d ago
CVE-2026-726327.1highkibanaObservable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclosure via Excavation (CAPEC-116).23d ago
CVE-2026-726297.1highkibanaAuthorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized cross-space access v23d ago
CVE-2026-726757.1highkibanaMissing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data mod23d ago
CVE-2026-561477.1highkibanaAuthorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized information disclosu46d ago
CVE-2026-726437.1highkibanaKibana Agent Builder determines whether a caller owns a private agent by comparing a stable user identifier when o23d ago
CVE-2026-726307.1highkibanaIncorrect Authorization (CWE-863) in Kibana Fleet can lead to privilege escalation via Privilege Abuse (CAPEC-122)23d ago
CVE-2026-269396.5mediumkibanaMissing Authorization (CWE-862) in Kibana’s server-side Detection Rule Management can lead to Unauthorized Endpoin170d ago
CVE-2026-269406.5mediumkibanaImproper Validation of Specified Quantity in Input (CWE-1284) in the Timelion visualization plugin in Kibana can l170d ago
CVE-2026-269315.7mediummetricbeatMemory Allocation with Excessive Size Value (CWE-789) in the Prometheus remote_write HTTP handler in Metricbeat ca170d ago

Filter the full tracker by Elastic

Our coverage of Elastic

npm

The security signal log tailing can't see: tracking npm cooldown removals with Elastic Agent

A new method using Elastic Agent's Common Expression Language (CEL) has been developed to monitor the npm package manager's "min-release-age" setting. This setting helps prevent the installation of recently compromised packages by introducing a delay. The CEL integration periodically snapshots .npmrc files, allowing for the detection of when this crucial security setting is removed, a scenario that traditional log tailing methods cannot identify.

vulnerability

Elastic goes all-in on Hacker Summer Camp at Black Hat and DEF CON in Las Vegas

Attack Discovery turns raw alerts into validated threats and Elastic Defend closes vulnerable driver gaps as fast as they're disclosed. Watch it all run against real attacks at the booth.

sochigh

Inside Elastic InfoSec's agentic SOC: cutting alert triage from 30 minutes to under 3

Elastic's InfoSec team has developed an automated security operations center (SOC) that significantly reduces alert triage time. By using deterministic queries and specialized AI agents, the system handles most alert investigations before human analysts are involved, cutting down a 30-minute process to under three minutes. This approach leverages Elastic's own technology stack and focuses on efficient, cost-effective automation to manage increasing alert volumes.

ai

From vulnerability report to CVE draft in minutes: how Elastic automated security advisories with AI

Elastic's InfoSec Product Security Team has developed an AI agent capable of generating comprehensive CVE security advisories. This agent utilizes generative AI and Retrieval-Augmented Generation (RAG) against MITRE's CWE and CAPEC databases, ensuring accurate classification and scoring. The process automates the drafting of advisories from raw vulnerability reports, significantly speeding up the disclosure phase.

threat intelligence

From API key to live threat detections in minutes: how Elastic Security ingests Google Threat Intelligence

Elastic Security now integrates with Google Threat Intelligence (GTI) to automatically ingest and analyze threat data. This integration allows for real-time detection of malicious indicators like IPs, domains, and file hashes within user telemetry. The system also supports on-demand enrichment of alerts using AI-driven workflows that query external sources like VirusTotal.