<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — Wazuh</title><description>Actively exploited vulnerabilities affecting Wazuh products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/wazuh.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2025-24016 — Wazuh Server Deserialization of Untrusted Data Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-24016</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-24016</guid><description>Wazuh is a widely deployed open-source security monitoring platform used by organizations to detect threats and manage compliance. This vulnerability allows an attacker to send maliciously crafted serialized data to a Wazuh server, which the server processes without proper validation, resulting in remote code execution. Because Wazuh servers typically hold privileged access to monitored endpoints and security event data, a successful exploit could give an attacker deep visibility into — and control over — an organization&apos;s entire monitored infrastructure.</description><pubDate>Tue, 10 Jun 2025 00:00:00 GMT</pubDate><category>Wazuh</category><category>Wazuh Server</category></item></channel></rss>