CVE-2018-8735: Nagios XI

High severity, CVSS 8.8. EPSS: 63.6% chance of exploitation in the next 30 days.

Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary commands on the target system, aka OS command injection.

Affected products

  • Nagios Nagios XI: from 5.2.0, before 5.4.13 (fixed in 5.4.13)

Published 2018-04-18. Last modified 2026-06-17.