CVE-2026-40941: Cacti

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a package import signature validation bypass allows which allows self-signed packages. This issue has been fixed in version 1.2.31.

Affected products

  • Cacti Cacti: before 1.2.31 (fixed in 1.2.31)

Published 2026-06-25. Last modified 2026-06-29.