CVE-2018-9276: Paessler PRTG Network Monitor OS Command Injection Vulnerability

High severity, CVSS 7.2. Actively exploited: in CISA KEV since 2025-02-04. EPSS: 87% chance of exploitation in the next 30 days.

An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with administrative privileges can exploit an OS command injection vulnerability (both on the server and on devices) by sending malformed parameters in sensor or notification management scenarios.

Affected products

  • Paessler PRTG Network Monitor: before 18.2.39 (fixed in 18.2.39); after 19.3.52, before 21.2.68 (fixed in 21.2.68)

Published 2018-07-02. Last modified 2026-06-17.