HomeIntelligenceBrief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical Remote Code Execution in Wazuh Cluster DAPI Protocol (CVE‑2026‑28220) Threatens SIEM Deployments

A deserialization bug (CVE‑2026‑28220) lets an attacker execute code as root on Wazuh master nodes. The flaw underscores the need for SOC 2‑aligned patch‑management and control‑mapping evidence.

LiveThreat™ Intelligence · 📅 August 12, 2026· 📰 zerodayinitiative.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
zerodayinitiative.com

Critical Remote Code Execution in Wazuh Cluster DAPI Protocol (CVE‑2026‑28220) Threatens SIEM Deployments

What It Is — A deserialization flaw in the Wazuh Cluster DAPI protocol (CVE‑2026‑28220) allows an attacker who can run low‑privileged code on a worker node to execute arbitrary commands as root on the master node.

Exploitability — CVSS 9.9 (Critical). Network‑adjacent attacker, low attack complexity, no user interaction required. No public exploit code yet, but the vulnerability is fully disclosed and can be weaponized quickly.

Affected Products — Wazuh (all versions prior to the 4.5.2 patch).

Why It Matters for Compliance & Audit Readiness

  • SOC 2 CC6.1 (System Operations) requires documented, monitored controls over system changes; an unpatched deserialization bug demonstrates a gap in change‑management and code‑integrity controls.
  • Continuous evidence of patch management is a core audit artifact; failure to remediate this flaw can be cited as a control deficiency during a SOC 2 audit.
  • Enterprise buyers increasingly demand proof that security‑tooling (e.g., SIEMs) is itself hardened, making this vulnerability a red flag in vendor‑risk assessments.

Recommended Actions

  • Apply the Wazuh 4.5.2 (or later) update that fixes CVE‑2026‑28220.
  • Verify that the patch is reflected in your configuration‑management database and capture the version as audit evidence.
  • Update your SOC 2 control mapping for “System Operations – Secure Configuration” and record remediation steps in your continuous‑compliance platform.

Source: Zero Day Initiative Advisory

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-528/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →