Critical Security Flaws in Cacti Threaten Remote Code Execution

Security researchers have discovered critical vulnerabilities in the Cacti open-source network monitoring framework, which could allow authenticated attackers to execute remote code on vulnerable instances. Identified as CVE-2025-22604, this vulnerability has been assigned a CVSS score of 9.1, indicating its high severity. With a flaw rooted in the multi-line SNMP result parser, authenticated users can inject malformed OIDs into the system response. This dangerous security issue affects Cacti versions prior to and including 1.2.28 and has been addressed in version 1.2.29. Exploiting this vulnerability can have serious implications, including unauthorized code execution, data theft, modification, or deletion, posing significant threats to any affected systems.

Another notable flaw, tagged as CVE-2025-24367, carries a CVSS score of 7.2 and enables authenticated attackers to create arbitrary PHP scripts in the web root. This is accomplished through the graph creation and template functionality of Cacti, leading to potential remote code execution. Both vulnerabilities underscore the urgent need for organizations employing Cacti to update their software to the latest version to minimize security risks. The discovery of CVE-2025-22604 is credited to a researcher known as u32i, whose work highlights the importance of continuous vulnerability assessments in open-source software.

Given previous incidents where Cacti’s vulnerabilities were actively exploited, the current flaws emphasize the importance of timely software patches to prevent possible security breaches. Organizations using Cacti should prioritize this update to protect their systems from potential compromise. By quickly applying patches and maintaining vigilant security practices, administrators can mitigate the risks associated with these critical vulnerabilities. Through this urgent reminder, the narrative stresses the essential role of proactive security measures in safeguarding network monitoring systems against evolving threats.

Explore more

Wise Joins PayNet to Launch DuitNow Services in Malaysia

The recent announcement that Wise has integrated with PayNet signifies a transformative shift in the Malaysian financial landscape by granting a non-bank fintech direct access to the national payment infrastructure. This strategic move enables the company to provide DuitNow QR and DuitNow Transfer services natively within its platform, effectively bridging the gap between international currency management and local payment utility.

Can You Now Pay for Emirates Flights with Crypto?

The rapid evolution of the global financial landscape has forced major international airlines to reconsider how they facilitate transactions with a tech-savvy customer base that increasingly favors decentralized assets. Emirates, a carrier synonymous with luxury and technological advancement, has consistently positioned itself at the vanguard of this digital shift by exploring the potential of blockchain and the metaverse. While travelers

Is Digital Lending in Africa a Revolution or a Debt Trap?

A street vendor in Nairobi can now secure a business loan in less time than it takes to brew a cup of tea, a feat that would have been statistically impossible just a few years ago. This shift represents a fundamental departure from the era of brick-and-mortar dominance where credit was the exclusive privilege of the wealthy and the formally

AXA Mansard Launches Karis WhatsApp Bot for Health Insurance

Navigating the complexities of healthcare administrative tasks often feels like an uphill battle for many policyholders who are already dealing with the physical and emotional stress of illness or injury. In the current landscape of 2026, the demand for immediate and frictionless communication has forced insurers to rethink their traditional service models, which frequently relied on cumbersome phone trees and

Martin Henley Leads the Evolution of Second-Wave Insurtech

The global insurance industry has historically struggled with a massive gap between the high expectations of digital transformation and the actual reality of fragmented back-office operations. Martin Henley, the founder and Group CEO of Mea Platform, recognized this disconnect while serving as the Group Chief Information Officer for XL Catlin. He observed that while billions of dollars were being poured