Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical Remote Code Execution in Wazuh Cluster DAPI Protocol (CVE‑2026‑28220) Threatens SIEM Deployments

A deserialization bug (CVE‑2026‑28220) lets an attacker execute code as root on Wazuh master nodes. The flaw underscores the need for SOC 2‑aligned patch‑management and control‑mapping evidence.

LiveThreat™ Intelligence · 📅 August 12, 2026· 📰 zerodayinitiative.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
3 recommended
📰
Source
zerodayinitiative.com

Critical Remote Code Execution in Wazuh Cluster DAPI Protocol (CVE‑2026‑28220) Threatens SIEM Deployments

What It Is — A deserialization flaw in the Wazuh Cluster DAPI protocol (CVE‑2026‑28220) allows an attacker who can run low‑privileged code on a worker node to execute arbitrary commands as root on the master node.

Exploitability — CVSS 9.9 (Critical). Network‑adjacent attacker, low attack complexity, no user interaction required. No public exploit code yet, but the vulnerability is fully disclosed and can be weaponized quickly.

Affected Products — Wazuh (all versions prior to the 4.5.2 patch).

Why It Matters for Compliance & Audit Readiness

  • SOC 2 CC6.1 (System Operations) requires documented, monitored controls over system changes; an unpatched deserialization bug demonstrates a gap in change‑management and code‑integrity controls.
  • Continuous evidence of patch management is a core audit artifact; failure to remediate this flaw can be cited as a control deficiency during a SOC 2 audit.
  • Enterprise buyers increasingly demand proof that security‑tooling (e.g., SIEMs) is itself hardened, making this vulnerability a red flag in vendor‑risk assessments.

Recommended Actions

  • Apply the Wazuh 4.5.2 (or later) update that fixes CVE‑2026‑28220.
  • Verify that the patch is reflected in your configuration‑management database and capture the version as audit evidence.
  • Update your SOC 2 control mapping for “System Operations – Secure Configuration” and record remediation steps in your continuous‑compliance platform.

Source: Zero Day Initiative Advisory

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-528/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →