Elastic issued security updates for Elasticsearch and Kibana (8.19.10, 9.1.10, 9.2.4) to address multiple vulnerabilities, including two high-severity issues with significant data-exposure risk. In Kibana, CVE-2026-0532 (CVSS 8.6) affects the Google Gemini connector and combines SSRF with external control of file name/path to enable arbitrary file disclosure and arbitrary outbound network requests via a specially crafted credentials JSON payload; exploitation requires authenticated access with privileges to create or modify connectors.
Elasticsearch addressed an information disclosure flaw in the yawkat LZ4 Java decompressor (CVE-2025-66566) that can leak prior buffer contents when an attacker sends specially crafted compressed input over the transport layer; affected versions span 7.14.0–7.17.29, 8.0.0–8.19.9, and 9.0.0–9.2.3. Elastic recommended upgrading to the fixed releases and provided mitigations for those unable to patch immediately, including switching transport.compression_scheme to deflate or disabling transport compression (transport.compress: false), while Kibana users can mitigate by disabling the vulnerable connector type via xpack.actions.enabledActionTypes configuration; Elastic Cloud Serverless was reported as remediated prior to public disclosure.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Elastic released updates addressing seven vulnerabilities across Elasticsearch, Kibana, Packetbeat, and Metricbeat, including a high-severity SSRF and arbitrary file disclosure issue in the Google Gemini connector and an information disclosure flaw in the yawkat LZ4 Java library. Elastic said versions 8.19.10, 9.1.10, and 9.2.4 resolve the issues and recommended immediate upgrades, with mitigations for the Elasticsearch transport-compression issue including switching to deflate or disabling compression.
Elastic published security advisories ESA-2026-05 and ESA-2026-07 announcing security updates for Kibana and Elasticsearch. The fixed versions listed were 8.19.10, 9.1.10, and 9.2.4.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcediscuss.elastic.co
Open sourcediscuss.elastic.co
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.