Checkmk Vulnerabilities

Comprehensive security vulnerability database for Checkmk products

Last updated: Feb 26, 2026
Total CVEs

1

Critical

0

With Exploits

3

Last 30 Days

1

Severity Distribution

Critical0
0%
High1
100%
Medium2
200%
Low0
0%
DescriptionVendor / ProductExploit Status
CVE-2025-649997.3

This vulnerability allows an attacker to inject malicious JavaScript into the monitoring logs of Checkmk, which can then be accessed through a specially crafted phishing link. To exploit this, the attacker needs to manipulate the output from a monitored host, making it essential for them to have some level of access to the system.

checkmkcheckmk
Exploit Available
about 1 month agoFeb 26, 2026

About Checkmk Security

This page tracks all publicly disclosed security vulnerabilities (CVEs) affecting Checkmk products. Our database is updated in real-time from the National Vulnerability Database (NVD) and enriched with exploit information from GitHub and other security research sources.

Each CVE listing includes CVSS severity scores, exploit availability status, AI-powered vulnerability summaries, and links to official patches and security advisories.