73,811 reachable PRTG instances: what exposure data does and does not prove
Vulnerability overview
Two PRTG issues were fixed in version 26.2.120.1449 and republished by CERT-Bund as WID-SEC-2026-3565: CVE-2026-4637, a reflected cross-site scripting flaw in error handling, and CVE-2026-4638, the disclosure of a stored domain password through script sensor output. Both were reported by SEC Consult after a January 2026 review.
Mechanism and exploitation conditions
CVE-2026-4637 reflects an unsanitised URL path into a 403 response and requires a signed-in victim to open a crafted link. CVE-2026-4638 places the value of %windowspassword into a VBScript error that PRTG renders on screen and requires a non-read-only account with sensor creation rights. Neither issue is a remote unauthenticated code execution path on its own; both need a human or a session in the loop.
Impact
Taken together the pair covers session theft and credential theft against the same class of host. A monitoring server rarely stands alone: it holds credentials for routers, switches, hypervisors, storage and application endpoints. a foothold on a monitoring platform is a foothold on the estate it watches.
Affected products and scope
- Affected: self-managed PRTG below 26.2.120.1449.
- Fixed: 26.2.120.1449, released 2026-06-03; Hosted Monitor upgraded 2026-06-24.
- Not affected: properly updated instances, and Hosted Monitor tenants after 2026-06-24.
Exposure context
A ZoomEye query for the PRTG product fingerprint returned 73,811 assets:
| Observation | Query | Count | Time |
|---|---|---|---|
| Product fingerprint | app="PRTG" |
73,811 | 2026-09-25T22:13:15Z |
| CVE index | vul.cve="CVE-2026-4637" |
0 | 2026-09-25T22:13:19Z |
Read those two rows carefully. The first row counts internet-reachable services that match a PRTG fingerprint. The second row counts assets that ZoomEye currently associates with this CVE, and the answer was zero, which means the CVE-indexed view contributes nothing here. Neither row shows which software build answers on a given address, and neither row proves that a specific host carries a vulnerable version. The honest summary is: the product is widely reachable, the vulnerable population is unknown, and the gap between those statements is exactly where an inventory is needed.
Remediation and mitigations
- Build a version inventory. Ask PRTG itself: compare the running build against 26.2.120.1449 rather than trusting a fingerprint query.
- Patch self-managed instances to 26.2.120.1449 or later, and confirm the fixed build through the PRTG web interface after the upgrade.
- Reduce reachability. Publish the PRTG interface only through a management network or a filtering reverse proxy, and enable HttpOnly and Secure on the session cookie.
- Treat the exposure figure as prioritisation input, then replace it with internal evidence.
References
- CERT-Bund advisory WID-SEC-2026-3565 (Paessler PRTG: Mehrere Schwachstellen), published 2026-09-23.
- SEC Consult Vulnerability Lab, Multiple Vulnerabilities in Paessler PRTG Network Monitor.
- Paessler Knowledge Base, Vulnerabilities in PRTG prior v26.2.120.1449.
- ZoomEye search app="PRTG", sub_type=all, executed 2026-09-25, returned 73,811 assets.
Top comments (0)