CVE-2025-15612: Wazuh

High severity, CVSS 8.1. EPSS: 0.2% chance of exploitation in the next 30 days.

Wazuh provisioning scripts and Dockerfiles contain an insecure transport vulnerability where curl is invoked with the -k/--insecure flag, disabling SSL/TLS certificate validation. Attackers with network access can perform man-in-the-middle attacks to intercept and modify downloaded dependencies or code during the build process, leading to remote code execution and supply chain compromise.

Affected products

  • Wazuh Wazuh: from 4.1.3, before 4.14.0 (fixed in 4.14.0)

Published 2026-03-27. Last modified 2026-10-07.