<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Graylog Server (V6.3.12, V7.0.7, V7.1.2) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/graylog-server-v6.3.12-v7.0.7-v7.1.2/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 29 Aug 2026 03:13:59 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/graylog-server-v6.3.12-v7.0.7-v7.1.2/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Graylog Syslog Parser Vulnerability Enabling Log Evasion</title><link>https://feed.craftedsignal.io/briefs/2026-08-graylog-syslog-parsing-vulnerability/</link><pubDate>Sat, 29 Aug 2026 03:13:59 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-graylog-syslog-parsing-vulnerability/</guid><description>A vulnerability in the Graylog syslog parser allows unauthenticated attackers to overwrite or discard logs from devices using key-value formats, such as Fortigate, facilitating log evasion.</description><content:encoded><![CDATA[<p>A security vulnerability identified as CVE-2026-55841 affects the Graylog syslog parser when processing key-value formatted messages, notably those generated by Fortigate network appliances. This flaw allows an attacker to manipulate the incoming syslog stream to either overwrite critical message fields or intentionally create malformed messages. Because Graylog discards messages that fail parsing, this mechanism provides a direct method for log evasion, effectively blinding security operations teams to malicious activity occurring within the network environment. The issue is present across Graylog Server versions 6.x prior to 6.3.12, 7.0.x prior to 7.0.7, and 7.1.x prior to 7.1.2. Defenders relying on these versions for Fortigate log ingestion are at risk of having their audit trails suppressed by sophisticated actors attempting to mask their tracks.</p>
<h2 id="impact">Impact</h2>
<p>The primary impact of this vulnerability is the loss of visibility into security events. By successfully triggering log parsing errors or field overwrites, an attacker can prevent security alerts from firing or remove evidence of lateral movement, persistence, or data exfiltration from the centralized logging repository. This allows attackers to operate within an environment while actively suppressing telemetry that would otherwise enable detection.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade Graylog Server immediately to versions 6.3.12, 7.0.7, or 7.1.2 to patch CVE-2026-55841.</li>
<li>Monitor the Indexing and Processing Failures Index in Graylog for a sudden spike in discarded messages, particularly those originating from Fortigate device sources.</li>
<li>Verify log integrity by correlating centralized Graylog logs with local logs stored on the Fortigate devices to identify potential gaps in coverage.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>logging</category><category>defense-evasion</category></item></channel></rss>