EXPOSURES › CVE-2025-24016
CVE-2025-24016
HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
⚡ RCE
⌖ EXPLOITED IN THE WILD
SHAME 72/100
rceexploited-in-wildunpatched
Wazuh Server RCE due to untrusted data deserialization
Wazuh Server suffered a remote code execution vulnerability due to untrusted data deserialization, actively exploited in the wild.
Shame score — Active exploitation in the wild indicates negligence in security updates.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PLAYERS IMPLICATED
DESCRIPTION
Wazuh contains a deserialization of untrusted data vulnerability that allows for remote code execution on Wazuh servers.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.