Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Wazuh

Wazuh Vendor Cyber Rating & Cyber Score

wazuh.com

Wazuh is a free and open-source security platform that unifies XDR and SIEM capabilities. It protects workloads across on-premises, virtualized, containerized, and cloud-based environments. Wazuh, with over 10 million downloads per year, has one of the largest open-source security communities in the world. Wazuh helps organizations of all sizes protect their data assets against security threats. Learn more about the project at wazuh.com


Wazuh A.I CyberSecurity Scoring

Wazuh
Company Information
Website:https://www.wazuh.com
Employees number:259
Number of followers:71,485
NAICS:541514
Industry Type:Computer and Network Security
Homepage:wazuh.com
Wazuh Risk Score (AI oriented)
Between 700 and 749
logo
WazuhComputer and Network Security
Updated:
15/06/2026
749/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Wazuh Global Score (TPRM)
xxxx
logo
WazuhComputer and Network Security
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Wazuh
WazuhModerate
Current Score
749Ba (MODERATE)
01000
2 incidents
-5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
754Before Incident
Vulnerability
15 Jun 2026Wazuh
Wazuh: Critical Wazuh Vulnerability Lets Attackers Tamper with Alerts and Delete Security Evidence

Critical Wazuh Manager Vulnerability Allows Remote Data Tampering and Evidence Deletion

749After Incident
CRITICAL-5
WAZ1781519186
Critical Wazuh Manager Vulnerability Allows Remote Data Tampering and Evidence Deletion A severe security flaw in Wazuh Manager (CVE pending, CVSS 10.0) has been disclosed, enabling remote attackers to manipulate security alerts, delete forensic evidence, and tamper with SIEM data. The vulnerability affects Wazuh Manager 5.0.0-beta1 and stems from an NDJSON injection flaw in the `inventory_sync` subsystem, where untrusted input in the `DataValue.index` field is improperly sanitized. The flaw allows malicious or compromised agents to inject arbitrary OpenSearch bulk operations by embedding crafted JSON fragments and newline characters into the `_index` field. While other fields (e.g., `_id`) are properly escaped, the `_index` field is appended without validation, enabling attackers to smuggle unauthorized actions such as delete, index, or update operations into requests. Exploiting this vulnerability requires no authentication due to insecure default configurations in `wazuh-authd`, which permits anonymous agent enrollment. Once enrolled, attackers can: - Delete arbitrary documents from Wazuh indices, erasing logs and alerts. - Modify vulnerability and inventory data for other agents. - Inject malicious content into Kibana dashboards for persistence or misdirection. - Manipulate cross-tenant data in shared environments. Researchers demonstrated a proof-of-concept (PoC) exploit over standard Wazuh communication channels (TCP ports 1514/1515), confirming that injected operations execute under the high-privileged OpenSearch credentials stored in Wazuh’s keystore. The flaw is classified under CWE-74 (Injection), CWE-93 (CRLF Injection), and CWE-863 (Incorrect Authorization), with the root cause tied to lack of input validation and improper neutralization of special characters. The issue has been patched in Wazuh 5.0.0-beta3 (GitHub advisory GHSA-ff9g-85jq-r3g3). Organizations using affected versions are advised to upgrade immediately and review logs for unauthorized index modifications. The vulnerability poses a critical risk to threat detection and response integrity, as attackers can silently alter security data to evade detection.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
IMPACT
Data Compromised: Security alerts, forensic evidence, SIEM data, vulnerability and inventory data, Kibana dashboardsSystems Affected: Wazuh Manager 5.0.0-beta1Operational Impact: Threat detection and response integrity compromised, potential evasion of security controlsBrand Reputation Impact: Critical risk to security product integrity
DATA BREACH
Type Of Data Compromised: Security logs, alerts, vulnerability data, inventory data, Kibana dashboard contentSensitivity Of Data: High (forensic evidence, security monitoring data)
MAY 2026
754Before Incident
APRIL 2026
754Before Incident
MARCH 2026
754Before Incident
FEBRUARY 2026
754Before Incident
JANUARY 2026
754Before Incident
DECEMBER 2025
754Before Incident
NOVEMBER 2025
754Before Incident
OCTOBER 2025
753Before Incident
SEPTEMBER 2025
753Before Incident
AUGUST 2025
753Before Incident
JULY 2025
753Before Incident
JUNE 2025
754Before Incident
Vulnerability
10 Jun 2025Wazuh
Wazuh: Unpatched Wazuh servers targeted by Mirai botnets (CVE-2025-24016)

Mirai Botnets Exploiting CVE-2025-24016 in Wazuh XDR/SIEM Platform

753After Incident
LOW-1
WAZ1766629994
Mirai Botnets Exploit Critical Wazuh XDR/SIEM Vulnerability (CVE-2025-24016) Akamai researchers have identified two Mirai botnets actively exploiting a critical remote code execution (RCE) vulnerability (CVE-2025-24016) in Wazuh, a widely used open-source XDR/SIEM platform. The flaw, an unsafe deserialization issue, affects Wazuh Manager versions 4.4.0 through 4.9.0 and can be triggered by attackers with API access—either through a compromised dashboard, server cluster, or, in some configurations, a compromised agent. Exploitation requires valid Wazuh API credentials, which attackers may obtain through prior breaches or credential theft. The vulnerability was patched in Wazuh 4.9.1 (October 2024), but public disclosure in February 2025 led to active attacks beginning in March 2025. The botnets leverage a public proof-of-concept (PoC) exploit released on February 21, delivering malicious shell scripts that download Mirai malware variants targeting multiple architectures, including those common in IoT devices. In May 2025, Akamai observed a third Mirai botnet attempting similar attacks, though targeting a non-standard Wazuh endpoint—likely another attempt to exploit the same flaw. Beyond Wazuh, these botnets also scan for legacy vulnerabilities in Hadoop YARN, TP-Link, ZTE, Huawei, and ZyXEL routers, as well as the RealTek SDK, demonstrating their adaptability in expanding their infrastructure. The attacks highlight how botnet operators rapidly weaponize public PoC exploits to grow their networks, often before organizations apply patches. This trend mirrors recent incidents, such as the exploitation of a Roundcube RCE flaw, where attackers reverse-engineered patches to exploit vulnerabilities before widespread remediation.
INCIDENT DETAILS -
TYPE
Botnet Exploitation
MOTIVATION
Botnet Expansion
IMPACT
Systems Affected: Wazuh Manager (versions 4.4.0 - 4.9.0), IoT devicesOperational Impact: Potential compromise of security monitoring and incident response capabilitiesBrand Reputation Impact: Potential reputational damage for Wazuh and affected organizations

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Wazuh ?
?
What was Wazuh's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Wazuh's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Wazuh's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Wazuh's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Wazuh's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Wazuh's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Wazuh's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Wazuh's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Wazuh's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Wazuh's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Wazuh's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Wazuh's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Wazuh ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Wazuh's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?