Detection signals for PRTG abuse: what to look for after CVE-2026-4637 and CVE-2026-4638
Vulnerability overview
PRTG builds before 26.2.120.1449 carry two reported weaknesses: reflected cross-site scripting in the error page path (CVE-2026-4637) and disclosure of a stored domain password through a script sensor error message (CVE-2026-4638). Both are recorded in CERT-Bund WID-SEC-2026-3565 and fixed in 26.2.120.1449.
Mechanism and exploitation conditions
The first issue needs a request whose path contains HTML and ends in .htm, followed by a signed-in user opening that link. The second needs an account with at least Pre-Configuration privileges to create an EXE/Script sensor and read the resulting error text. Both leave traces in places monitoring teams already collect.
Impact
Successful exploitation yields either an administrator session cookie or a working domain credential. Each result is enough to move laterally inside the network that PRTG monitors, which is usually the whole network.
Affected products and scope
- Affected: PRTG Network Monitor below 26.2.120.1449 (self-managed).
- Fixed: 26.2.120.1449, 2026-06-03. CERT-Bund states a patch exists.
- Reporter: SEC Consult Vulnerability Lab, January 2026.
Exposure context
ZoomEye records 73,811 assets matching app="PRTG" as of 2026-09-25, while vul.cve="CVE-2026-4637" returned zero. The difference matters for detection work: the population at risk is defined by software version, not by a search-engine label, so telemetry has to come from the fleet itself.
Detection and hunting signals
Web server and reverse proxy logs
- Requests where the path contains
<,>,script,alertordocument.cookieand ends in.htm. - Repeated 403 responses for the same client address across paths that look like payload fragments.
- Any request whose user agent is tied to a link opened from mail or chat rather than the normal administrator workstation.
PRTG application logs
- New EXE/Script sensors created by accounts that do not normally create sensors.
- Sensor messages containing
Type mismatchorMicrosoft VBScript runtime error. - Sensor definitions whose arguments reference
%windowspassword.
Identity telemetry
- PRTG administrator sessions created from an address that has not been seen before.
- Authentication events for the account named in a sensor definition, clustered shortly after a sensor error appears.
Each signal is individually weak. A Type mismatch message can come from a genuine broken script, and a .htm request with angle brackets can come from a scanner. What raises confidence is the combination, from the same host, inside a short window.
Remediation and mitigations
- Upgrade to 26.2.120.1449 or later and confirm the build number.
- Rotate the credentials used for Windows sensor authentication and review what else the account can reach.
- Invalidate active PRTG sessions after a suspected CVE-2026-4637 delivery.
- Convert the hunting signals above into standing rules so the next advisory does not start from zero.
References
- CERT-Bund advisory WID-SEC-2026-3565 (Paessler PRTG: Mehrere Schwachstellen), published 2026-09-23.
- SEC Consult Vulnerability Lab, Multiple Vulnerabilities in Paessler PRTG Network Monitor.
- Paessler Knowledge Base, Vulnerabilities in PRTG prior v26.2.120.1449.
- ZoomEye search app="PRTG", sub_type=all, executed 2026-09-25, returned 73,811 assets.
Top comments (0)