German government CERT advisories reported multiple vulnerabilities in Grafana, the widely used observability and dashboard platform. Two separate dCERT notices identified Grafana as affected, indicating that security issues were disclosed across more than one advisory rather than as a single isolated flaw.
The advisories provide limited public detail, but the repeated notices indicate an ongoing need for organizations running Grafana to review vendor guidance, identify affected versions, and apply available patches or mitigations. Because Grafana is commonly deployed to monitor infrastructure, applications, and security telemetry, unpatched weaknesses could expose sensitive operational data or create opportunities for further compromise depending on the impacted components.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
dCERT published advisory 2026-1114 for a Grafana vulnerability that allows information disclosure. This is a separate disclosure event from the earlier Grafana advisories already in the timeline.
dCERT published advisory 2026-0887 covering multiple vulnerabilities in Grafana. This represents a later, separate advisory event related to Grafana vulnerabilities.
dCERT published advisory 2026-0221 for multiple vulnerabilities affecting Grafana. The reference indicates this was a distinct disclosure event by the German CERT.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
dcert.de
Open sourcedcert.de
Open sourcedcert.de
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.