<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Wazuh (&lt; 4.14.3) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/wazuh--4.14.3/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 28 Aug 2026 19:17:51 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/wazuh--4.14.3/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Wazuh Cluster Mode Insecure Deserialization Vulnerability (CVE-2026-25769)</title><link>https://feed.craftedsignal.io/briefs/2026-08-wazuh-rce/</link><pubDate>Fri, 28 Aug 2026 19:17:51 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-wazuh-rce/</guid><description>An insecure deserialization vulnerability in Wazuh cluster communication allows a compromised worker node to achieve remote code execution as root on the master node.</description><content:encoded><![CDATA[<p>CVE-2026-25769 is a critical insecure deserialization vulnerability affecting the cluster communication mechanism in Wazuh versions prior to 4.14.3. The flaw resides in how the Wazuh master node processes serialized data received from worker nodes within the cluster architecture. If an attacker successfully compromises a single worker node, they can leverage this vulnerability to send maliciously crafted serialized objects to the master node. Upon deserialization, these objects facilitate arbitrary command execution with root privileges on the master node. Given the high CVSS score of 9.1, this vulnerability poses a severe risk to the integrity of the entire security monitoring infrastructure, as a compromise of a worker node leads to a full takeover of the central management server.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for full system compromise of the Wazuh master node with root-level access. This results in the complete loss of confidentiality, integrity, and availability for the security monitoring platform, potentially enabling attackers to disable detection capabilities, exfiltrate security logs, or pivot further into the internal network.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security operations and IT teams:</p>
<ul>
<li>Upgrade all Wazuh instances in cluster configurations to version 4.14.3 or later immediately to patch CVE-2026-25769.</li>
<li>Restrict network access to the Wazuh cluster communication ports strictly to authorized worker nodes using host-based firewalls or network access control lists.</li>
<li>Audit existing Wazuh worker nodes for signs of prior compromise, as a compromised worker is the prerequisite for exploiting this vulnerability.</li>
<li>Review cluster communication logs for anomalies in traffic patterns or unexpected payload sizes originating from worker nodes.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>rce</category><category>wazuh</category></item></channel></rss>