{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3agraylogserver/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:graylog:server:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-55841"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Graylog Server (v6.3.12, v7.0.7, v7.1.2)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","logging","defense-evasion"],"_cs_type":"advisory","_cs_vendors":["Graylog"],"content_html":"\u003cp\u003eA security vulnerability identified as CVE-2026-55841 affects the Graylog syslog parser when processing key-value formatted messages, notably those generated by Fortigate network appliances. This flaw allows an attacker to manipulate the incoming syslog stream to either overwrite critical message fields or intentionally create malformed messages. Because Graylog discards messages that fail parsing, this mechanism provides a direct method for log evasion, effectively blinding security operations teams to malicious activity occurring within the network environment. The issue is present across Graylog Server versions 6.x prior to 6.3.12, 7.0.x prior to 7.0.7, and 7.1.x prior to 7.1.2. Defenders relying on these versions for Fortigate log ingestion are at risk of having their audit trails suppressed by sophisticated actors attempting to mask their tracks.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe primary impact of this vulnerability is the loss of visibility into security events. By successfully triggering log parsing errors or field overwrites, an attacker can prevent security alerts from firing or remove evidence of lateral movement, persistence, or data exfiltration from the centralized logging repository. This allows attackers to operate within an environment while actively suppressing telemetry that would otherwise enable detection.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Graylog Server immediately to versions 6.3.12, 7.0.7, or 7.1.2 to patch CVE-2026-55841.\u003c/li\u003e\n\u003cli\u003eMonitor the Indexing and Processing Failures Index in Graylog for a sudden spike in discarded messages, particularly those originating from Fortigate device sources.\u003c/li\u003e\n\u003cli\u003eVerify log integrity by correlating centralized Graylog logs with local logs stored on the Fortigate devices to identify potential gaps in coverage.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-29T03:13:59Z","date_published":"2026-08-29T03:13:59Z","id":"https://feed.craftedsignal.io/briefs/2026-08-graylog-syslog-parsing-vulnerability/","summary":"A vulnerability in the Graylog syslog parser allows unauthenticated attackers to overwrite or discard logs from devices using key-value formats, such as Fortigate, facilitating log evasion.","title":"Graylog Syslog Parser Vulnerability Enabling Log Evasion","url":"https://feed.craftedsignal.io/briefs/2026-08-graylog-syslog-parsing-vulnerability/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:graylog:server:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}