DEV Community

yutianle
yutianle

Posted on

Detection signals for PRTG abuse: what to look for after CVE-2026-4637 and CVE-2026-4638

Detection signals for PRTG abuse: what to look for after CVE-2026-4637 and CVE-2026-4638

Vulnerability overview

PRTG builds before 26.2.120.1449 carry two reported weaknesses: reflected cross-site scripting in the error page path (CVE-2026-4637) and disclosure of a stored domain password through a script sensor error message (CVE-2026-4638). Both are recorded in CERT-Bund WID-SEC-2026-3565 and fixed in 26.2.120.1449.

Mechanism and exploitation conditions

The first issue needs a request whose path contains HTML and ends in .htm, followed by a signed-in user opening that link. The second needs an account with at least Pre-Configuration privileges to create an EXE/Script sensor and read the resulting error text. Both leave traces in places monitoring teams already collect.

Impact

Successful exploitation yields either an administrator session cookie or a working domain credential. Each result is enough to move laterally inside the network that PRTG monitors, which is usually the whole network.

Affected products and scope

  • Affected: PRTG Network Monitor below 26.2.120.1449 (self-managed).
  • Fixed: 26.2.120.1449, 2026-06-03. CERT-Bund states a patch exists.
  • Reporter: SEC Consult Vulnerability Lab, January 2026.

Exposure context

ZoomEye records 73,811 assets matching app="PRTG" as of 2026-09-25, while vul.cve="CVE-2026-4637" returned zero. The difference matters for detection work: the population at risk is defined by software version, not by a search-engine label, so telemetry has to come from the fleet itself.

Detection and hunting signals

Web server and reverse proxy logs

  • Requests where the path contains <, >, script, alert or document.cookie and ends in .htm.
  • Repeated 403 responses for the same client address across paths that look like payload fragments.
  • Any request whose user agent is tied to a link opened from mail or chat rather than the normal administrator workstation.

PRTG application logs

  • New EXE/Script sensors created by accounts that do not normally create sensors.
  • Sensor messages containing Type mismatch or Microsoft VBScript runtime error.
  • Sensor definitions whose arguments reference %windowspassword.

Identity telemetry

  • PRTG administrator sessions created from an address that has not been seen before.
  • Authentication events for the account named in a sensor definition, clustered shortly after a sensor error appears.

Each signal is individually weak. A Type mismatch message can come from a genuine broken script, and a .htm request with angle brackets can come from a scanner. What raises confidence is the combination, from the same host, inside a short window.

Remediation and mitigations

  1. Upgrade to 26.2.120.1449 or later and confirm the build number.
  2. Rotate the credentials used for Windows sensor authentication and review what else the account can reach.
  3. Invalidate active PRTG sessions after a suspected CVE-2026-4637 delivery.
  4. Convert the hunting signals above into standing rules so the next advisory does not start from zero.

References

  • CERT-Bund advisory WID-SEC-2026-3565 (Paessler PRTG: Mehrere Schwachstellen), published 2026-09-23.
  • SEC Consult Vulnerability Lab, Multiple Vulnerabilities in Paessler PRTG Network Monitor.
  • Paessler Knowledge Base, Vulnerabilities in PRTG prior v26.2.120.1449.
  • ZoomEye search app="PRTG", sub_type=all, executed 2026-09-25, returned 73,811 assets.

Top comments (0)