VendorsNagiosfusion2024
Vulnerabilities

Nagios Fusion 2024

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2025-60425
Nagios Fusion v2024R1.2 and v2024R2 does not invalidate already existing session tokens when the two-factor authentication mechanism is enabled, allowing attackers to perform a session hijacking attack.
Published 2025-10-27 · Analyzed
8.6EPSS 0.009
CVE-2025-60424
A lack of rate limiting in the OTP verification component of Nagios Fusion v2024R1.2 and v2024R2 allows attackers to bypass authentication via a bruteforce attack.
Published 2025-10-27 · Analyzed
7.6EPSS 0.007