CVE-2026-38968: Ntop Ntopng
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result, fresh authenticated logins can receive deterministic or colliding session cookies under attacker-controlled timing.
Affected products
- Ntop Ntopng: up to and including 6.6
Published 2026-07-02. Last modified 2026-07-08.