Dev.to Security ๐Ÿ” Cybersecurity ๐Ÿ‘ 0 ๐Ÿ“– 2 min read

73,811 reachable PRTG instances: what exposure data does and does not prove

73,811 reachable PRTG instances: what exposure data does and does not prove Vulnerability overview Two PRTG issues were fixed in version 26.2.120.1449 and republished by CERT-Bund as WID-SEC-2026-3565: CVE-2

73,811 reachable PRTG instances: what exposure data does and does not prove

Vulnerability overview

Two PRTG issues were fixed in version 26.2.120.1449 and republished by CERT-Bund as WID-SEC-2026-3565: CVE-2026-4637, a reflected cross-site scripting flaw in error handling, and CVE-2026-4638, the disclosure of a stored domain password through script sensor output. Both were reported by SEC Consult after a January 2026 review.

Mechanism and exploitation conditions

CVE-2026-4637 reflects an unsanitised URL path into a 403 response and requires a signed-in victim to open a crafted link. CVE-2026-4638 places the value of %windowspassword into a VBScript error that PRTG renders on screen and requires a non-read-only account with sensor creation rights. Neither issue is a remote unauthenticated code execution path on its own; both need a human or a session in the loop.

Impact

Taken together the pair covers session theft and credential theft against the same class of host. A monitoring server rarely stands alone: it holds credentials for routers, switches, hypervisors, storage and application endpoints. a foothold on a monitoring platform is a foothold on the estate it watches.

Affected products and scope

  • Affected: self-managed PRTG below 26.2.120.1449.
  • Fixed: 26.2.120.1449, released 2026-06-03; Hosted Monitor upgraded 2026-06-24.
  • Not affected: properly updated instances, and Hosted Monitor tenants after 2026-06-24.

Exposure context

A ZoomEye query for the PRTG product fingerprint returned 73,811 assets:

Observation Query Count Time
Product fingerprint app="PRTG" 73,811 2026-09-25T22:13:15Z
CVE index vul.cve="CVE-2026-4637" 0 2026-09-25T22:13:19Z

Read those two rows carefully. The first row counts internet-reachable services that match a PRTG fingerprint. The second row counts assets that ZoomEye currently associates with this CVE, and the answer was zero, which means the CVE-indexed view contributes nothing here. Neither row shows which software build answers on a given address, and neither row proves that a specific host carries a vulnerable version. The honest summary is: the product is widely reachable, the vulnerable population is unknown, and the gap between those statements is exactly where an inventory is needed.

Remediation and mitigations

  1. Build a version inventory. Ask PRTG itself: compare the running build against 26.2.120.1449 rather than trusting a fingerprint query.
  2. Patch self-managed instances to 26.2.120.1449 or later, and confirm the fixed build through the PRTG web interface after the upgrade.
  3. Reduce reachability. Publish the PRTG interface only through a management network or a filtering reverse proxy, and enable HttpOnly and Secure on the session cookie.
  4. Treat the exposure figure as prioritisation input, then replace it with internal evidence.

References

  • CERT-Bund advisory WID-SEC-2026-3565 (Paessler PRTG: Mehrere Schwachstellen), published 2026-09-23.
  • SEC Consult Vulnerability Lab, Multiple Vulnerabilities in Paessler PRTG Network Monitor.
  • Paessler Knowledge Base, Vulnerabilities in PRTG prior v26.2.120.1449.
  • ZoomEye search app="PRTG", sub_type=all, executed 2026-09-25, returned 73,811 assets.
๐Ÿ“ฐ Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes โ€” full credit and traffic to the original publisher.