Known Vulnerabilities for Ntopng by Ntop
Listed below are 9 of the newest known vulnerabilities associated with "Ntopng" by "Ntop".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-86091 json | ntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing authenticated non-adminis... | Not Provided | 2026-09-04 | 2026-09-08 |
| CVE-2026-86090 json | ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 handlers. Authe... | Not Provided | 2026-09-04 | 2026-09-14 |
| CVE-2026-84990 json | ntopng is a web-based network traffic monitoring application. Prior to 6.7.260718, scripts/lua/rest/v2/get/system/configurati... | Not Provided | 2026-09-21 | 2026-09-21 |
| CVE-2026-84989 json | ntopng is a web-based network traffic monitoring application. In versions 6.7.0 through 6.7.260717, two REST v2 endpoints tha... | Not Provided | 2026-09-03 | 2026-09-03 |
| CVE-2026-83621 json | ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, POST /lua/rest/v2/edit/system/edit_blackli... | Not Provided | 2026-09-21 | 2026-09-21 |
| CVE-2026-82412 json | ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, the vulnerability-scan endpoints scripts/l... | Not Provided | 2026-09-21 | 2026-09-21 |
| CVE-2026-38968 json | ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifi... | Not Provided | 2026-07-02 | 2026-07-06 |
| CVE-2018-12520 json | An issue was discovered in ntopng 3.4 before 3.4.180617. The PRNG involved in the generation of session IDs is not seeded at ... | 8.1 - HIGH | 2018-07-05 | 2019-10-03 |
| CVE-2017-7459 json | Not Provided | 2017-06-26 | 2025-04-20 | |
| CVE-2017-7458 json | Not Provided | 2017-06-26 | 2025-04-20 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ntop | Ntopng | 3.8 | |||
| Application | Ntop | Ntopng | 3.6.1 | |||
| Application | Ntop | Ntopng | 3.6 | |||
| Application | Ntop | Ntopng | 3.4.180617 | |||
| Application | Ntop | Ntopng | 3.4 | |||
| Application | Ntop | Ntopng | 3.2 | |||
| Application | Ntop | Ntopng | 3.0 | |||
| Application | Ntop | Ntopng | 2.4 | |||
| Application | Ntop | Ntopng | 2.0.151021 | |||
| Application | Ntop | Ntopng | 1.2.1 | |||
| Application | Ntop | Ntopng | 1.2.0 | |||
| Application | Ntop | Ntopng | 1.1 |