📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global vulnerability Technology/Software Development CRITICAL 19m Global general Industrial Control Systems/Manufacturing HIGH 31m Global data_breach Social Media and Virtual Reality Platforms HIGH 41m Global vulnerability Enterprise Security / All Sectors HIGH 42m Global apt Government and Defense CRITICAL 1h Global general Technology / Consumer Protection MEDIUM 1h Global vulnerability Information Technology and Security CRITICAL 1h Global vulnerability Information Technology CRITICAL 2h Global apt Infrastructure, Transportation, Finance/Investment HIGH 2h Global vulnerability Information Technology and Infrastructure HIGH 3h Global vulnerability Technology/Software Development CRITICAL 19m Global general Industrial Control Systems/Manufacturing HIGH 31m Global data_breach Social Media and Virtual Reality Platforms HIGH 41m Global vulnerability Enterprise Security / All Sectors HIGH 42m Global apt Government and Defense CRITICAL 1h Global general Technology / Consumer Protection MEDIUM 1h Global vulnerability Information Technology and Security CRITICAL 1h Global vulnerability Information Technology CRITICAL 2h Global apt Infrastructure, Transportation, Finance/Investment HIGH 2h Global vulnerability Information Technology and Infrastructure HIGH 3h Global vulnerability Technology/Software Development CRITICAL 19m Global general Industrial Control Systems/Manufacturing HIGH 31m Global data_breach Social Media and Virtual Reality Platforms HIGH 41m Global vulnerability Enterprise Security / All Sectors HIGH 42m Global apt Government and Defense CRITICAL 1h Global general Technology / Consumer Protection MEDIUM 1h Global vulnerability Information Technology and Security CRITICAL 1h Global vulnerability Information Technology CRITICAL 2h Global apt Infrastructure, Transportation, Finance/Investment HIGH 2h Global vulnerability Information Technology and Infrastructure HIGH 3h
Vulnerabilities

CVE-2025-64999

Medium
Improper neutralization of input in Checkmk versions 2.4.0 before 2.4.0p22, and 2.3.0 before 2.3.0p43 allows an attacker that can manipulate a host's check output to inject malicious JavaScript into t
CWE-79 — Weakness Type
Published: Feb 26, 2026  ·  Modified: Mar 5, 2026  ·  Source: NVD
CVSS v3
5.4
🔗 NVD Official
📄 Description (English)

Improper neutralization of input in Checkmk versions 2.4.0 before 2.4.0p22, and 2.3.0 before 2.3.0p43 allows an attacker that can manipulate a host's check output to inject malicious JavaScript into the Synthetic Monitoring HTML logs, which can then be accessed via a crafted phishing link.

🤖 AI Executive Summary

CVE-2025-64999 is a stored cross-site scripting (XSS) vulnerability in Checkmk monitoring software affecting versions 2.3.0 before p43 and 2.4.0 before p22. An attacker with the ability to manipulate host check outputs can inject malicious JavaScript into Synthetic Monitoring HTML logs, which executes when accessed via phishing links. While currently unpatched, the attack requires internal access to manipulate check outputs, limiting immediate external threat but posing significant risk to monitoring infrastructure integrity.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: May 26, 2026 10:19
🇸🇦 Saudi Arabia Impact Assessment
Saudi organizations using Checkmk for infrastructure monitoring face moderate risk. Primary impact sectors include: (1) Government agencies and NCA using Checkmk for IT infrastructure monitoring; (2) Banking sector (SAMA-regulated) using Checkmk for system health monitoring; (3) Energy sector (ARAMCO and related entities) relying on Checkmk for critical infrastructure monitoring; (4) Telecom operators (STC, Mobily) using Checkmk for network monitoring. The vulnerability requires internal access to manipulate check outputs, making it primarily a risk from compromised monitoring agents or insider threats. However, successful exploitation could lead to credential theft, lateral movement, or system compromise through phishing links sent to monitoring personnel.
🏢 Affected Saudi Sectors
Government Banking Energy Telecommunications Healthcare Critical Infrastructure
⚖️ Saudi Risk Score (AI)
5.8
/ 10.0
🔧 Remediation Steps (English)
Immediate Actions:
1. Identify all Checkmk instances in your environment running versions 2.3.0 (before p43) or 2.4.0 (before p22)
2. Restrict access to Checkmk monitoring interfaces to authorized personnel only
3. Implement network segmentation to isolate Checkmk infrastructure from untrusted networks
4. Review and audit all monitoring agent configurations for unauthorized modifications

Patching Guidance:
1. Upgrade Checkmk 2.3.0 installations to version 2.3.0p43 or later
2. Upgrade Checkmk 2.4.0 installations to version 2.4.0p22 or later
3. Test patches in non-production environments before deployment
4. Schedule maintenance windows for production upgrades

Compensating Controls (if patching delayed):
1. Implement Web Application Firewall (WAF) rules to detect and block JavaScript injection patterns in Checkmk logs
2. Deploy Content Security Policy (CSP) headers to prevent inline script execution
3. Enforce strict input validation on all monitoring agent outputs
4. Implement HTML entity encoding for all user-controllable data in log displays
5. Use security headers: X-Content-Type-Options: nosniff, X-Frame-Options: DENY

Detection Rules:
1. Monitor for suspicious JavaScript patterns in check output data: <script>, javascript:, onerror=, onload=
2. Alert on unusual modifications to monitoring agent configurations
3. Track access to Synthetic Monitoring HTML logs from external or suspicious sources
4. Monitor for phishing emails containing Checkmk log links with encoded payloads
5. Implement SIEM rules to detect XSS payload indicators in Checkmk API calls and log submissions
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تحديد جميع مثيلات Checkmk في بيئتك التي تعمل بالإصدارات 2.3.0 (قبل p43) أو 2.4.0 (قبل p22)
2. تقييد الوصول إلى واجهات مراقبة Checkmk للموظفين المصرح لهم فقط
3. تنفيذ تقسيم الشبكة لعزل بنية Checkmk الأساسية عن الشبكات غير الموثوقة
4. مراجعة وتدقيق جميع تكوينات وكيل المراقبة للتعديلات غير المصرح بها

إرشادات التصحيح:
1. ترقية تثبيتات Checkmk 2.3.0 إلى الإصدار 2.3.0p43 أو أحدث
2. ترقية تثبيتات Checkmk 2.4.0 إلى الإصدار 2.4.0p22 أو أحدث
3. اختبار التصحيحات في بيئات غير الإنتاج قبل النشر
4. جدولة نوافذ الصيانة لترقيات الإنتاج

الضوابط البديلة (إذا تأخر التصحيح):
1. تنفيذ قواعد جدار حماية تطبيقات الويب (WAF) للكشف عن أنماط حقن JavaScript وحجبها في سجلات Checkmk
2. نشر رؤوس سياسة الأمان (CSP) لمنع تنفيذ البرامج النصية المضمنة
3. فرض التحقق الصارم من الإدخال على جميع مخرجات وكيل المراقبة
4. تنفيذ ترميز كيان HTML لجميع البيانات القابلة للتحكم من قبل المستخدم في عروض السجل
5. استخدام رؤوس الأمان: X-Content-Type-Options: nosniff, X-Frame-Options: DENY

قواعد الكشف:
1. مراقبة أنماط JavaScript المريبة في بيانات مخرجات الفحص: <script>, javascript:, onerror=, onload=
2. التنبيه على التعديلات غير العادية على تكوينات وكيل المراقبة
3. تتبع الوصول إلى سجلات المراقبة الاصطناعية من مصادر خارجية أو مريبة
4. مراقبة رسائل البريد الإلكتروني للتصيد الاحتيالي التي تحتوي على روابط سجل Checkmk بحمولات مشفرة
5. تنفيذ قواعس SIEM للكشف عن مؤشرات حمولة XSS في استدعاءات Checkmk API وتقديمات السجل
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.14.2.1 - Information security requirements for supplier relationships ECC 2024 A.14.2.5 - Addressing information security in supplier agreements ECC 2024 A.5.23 - Web application security controls ECC 2024 A.6.14 - Secure development and change management
🔵 SAMA CSF
SAMA CSF 1.1 - Governance and Risk Management SAMA CSF 2.2 - Information and Communications Technology (ICT) Security SAMA CSF 2.2.1 - Access Control and Authentication SAMA CSF 2.2.2 - Data Protection and Encryption SAMA CSF 2.2.4 - Monitoring and Incident Management
🟡 ISO 27001:2022
ISO 27001:2022 A.5.23 - Web application security ISO 27001:2022 A.6.5 - Access control ISO 27001:2022 A.8.22 - Monitoring activities ISO 27001:2022 A.8.28 - Secure coding
🟣 PCI DSS v4.0.1
PCI DSS 6.5.1 - Injection flaws prevention PCI DSS 6.5.7 - Cross-site scripting (XSS) prevention PCI DSS 11.3 - Penetration testing and vulnerability scanning
📦 Affected Products / CPE 50 entries
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.3.0
checkmk:checkmk:2.4.0
📊 CVSS Score
5.4
/ 10.0 — Medium
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionR — Required
ScopeC — Changed
ConfidentialityL — Low / Local
IntegrityL — Low / Local
AvailabilityN — None / Network
📋 Quick Facts
Severity Medium
CVSS Score5.4
CWECWE-79
Exploit No
Patch ✗ No
Published 2026-02-26
Source Feed nvd
Views 7
🇸🇦 Saudi Risk Score
5.8
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-79
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.