Upcoming Pandora FMS training: August 24. More information →

Patch Notes

777.17 LTS

We only release patches for Long Time Support (LTS) versions, except for some particular cases where we do so for Feature Release versions.

Security patches are developed as soon as possible after the vulnerability is detected. Patches for LTS versions usually include critical-bug troubleshooting and solutions to security problems.

Version: Pandora FMS 777 LTS
Release date: February 24, 2026

LTS Patches

We only release patches for Long Time Support (LTS) versions, except for some particular cases where we do so for Feature Release (FR) versions.

Security patches are developed as soon as possible after the vulnerability is detected. Patches for LTS versions usually include critical-bug troubleshooting and solutions to security problems.

Bug fixes

FIX LTS# GitLab# Description

17919

14185, 17372

In Dashboards with event widgets, the visual style has been refined and now displays and maintains all elements in the same way.

18079

17586

The process for saving NCM agents has been corrected.

18267

17717

The display of IP addresses and MAC addresses has been fixed in the SNMP agent interfaces.

18269

17495

The display of regular expressions in external monitoring policy alerts in the Web Console has been corrected.

18270

17453

The filtering by alert status was corrected in the agent.

18357

18348

In Command Center, Linked Visual Consoles, it has been corrected that when elements are disabled, they no longer affect higher levels.

18525

18452

The monthly SLA report (PDF file) has been fixed for all languages other than English.

18597

18596

Added exception routine for the “Data_in_files” module of the PFMS self-monitoring agent.

18780

14200

Corrected “Select All” behavior for agents and modules in Mass Module Editing.

18821, 19735

18820

Time thresholds applied to alerts through monitoring policies have been corrected.

18883

18569

The “_start_date_” and “_end_date_” macros in reports were corrected to return the correct values.

18887

18851

Fixed module event report.

19084

18042

The count of agents for license purposes has been corrected.

19085

14333, 19046

In the bulk editing of modules, the display of agents whose modules were selected first has been fixed.

19100

18040

In event alerts, rule applications whose conditions include tag values have been fixed.

19543

18191

Fixed the inclusion of IP addresses when creating modules using the SNMP interface wizard.

19556

16132

The creation of users and their logins in the Web Console have been fixed when SAML (user ID attribute field) is used as the authentication method in Pandora FMS.

Improvements and small changes

FIX LTS# GitLab# Description

18268

16083

In string-type modules, their display has been improved by the Web Console, taking into account whether the check result has more than 200 characters and whether it contains line breaks.

Known Changes and Limitations

FIX LTS# GitLab# Description

18342 (23301, 23343)

N/A

The links to the old PFMS library have been replaced with a new notice directing users to the new website.

18696

18695

The “Allow non-consecutive patches” token being disabled also allows you to upgrade to the next LTS version.

Fixed vulnerabilities

See our Common Vulnerabilities and Exposures (CVE®) list.

FIX LTS# GitLab# Description

19199

CVE-2026-34188

Special thanks to: Pedro J. Núñez-Cacho Fuentes

19178

The arbitrary SQL injection vulnerability involving access to custom event responses has been fixed.

19200

CVE-2026-34187

Special thanks to: Pedro J. Núñez-Cacho Fuentes

19177

Numeric variable types were updated to prevent SQL injection in AJAX.

19201

CVE-2026-34186

Special thanks to: Pedro J. Núñez-Cacho Fuentes

19176

The arbitrary SQL injection vulnerability involving access to custom agent fields has been fixed.

19202

CVE-2026-30813

Special thanks to: Pedro J. Núñez-Cacho Fuentes

19174

A vulnerability involving the injection of arbitrary SQL code through access to and queries of modules in the Dashboards feature has been fixed.

19203

CVE-2026-30812

Special thanks to: Pedro J. Núñez-Cacho Fuentes

19173

A vulnerability involving unauthorized code injection via event comments (XSS) has been fixed.

19204

CVE-2026-30811

Special thanks to: Pedro J. Núñez-Cacho Fuentes

19172

The leftover files and functions from discontinued features—which had allowed access to important and sensitive information—were permanently deleted.

19205

CVE-2026-30810

Special thanks to: Pedro J. Núñez-Cacho Fuentes

19171

The ability to execute PFMS 1.0 API commands via the web console was restricted to superadmin users (additional security measures were also implemented).

19206

CVE-2026-30809

Special thanks to: Pedro J. Núñez-Cacho Fuentes

19170

Fixed a command injection vulnerability in web module debugging.

19207

CVE-2026-30808

Special thanks to: Pedro J. Núñez-Cacho Fuentes

19169

Related: 26, 14673

Added regeneration of the PHPSESSID cookie after a user successfully logs in to the PFMS Web Console.

19208

CVE-2026-30807

Special thanks to: Pedro J. Núñez-Cacho Fuentes

19168, 19163

Fixed CSRF validation on PFMS Web Console extension pages.

19209

CVE-2026-30806

Special thanks to: Pedro J. Núñez-Cacho Fuentes

19167

The command injection via WHOIS into the operating system has been fixed.

19211

CVE-2026-30805

Special thanks to: Pedro J. Núñez-Cacho Fuentes

19166, 19740

Random password generation has been added to the PFMS API upon installation. For existing installations, a persistent warning has been added until the password is changed.

19212

CVE-2026-30804

Special thanks to: Pedro J. Núñez-Cacho Fuentes

19163

Registration, integration and validation of extensions for the PFMS Web Console are fixed.

19213

18688

The search for text strings in custom fields (such as password fields) has been removed.

For more information about previous versions, visit the release notes section of our website.

For the minimum system requirements, see the installation section of our official documentation.

The server update is performed in conjunction with the Console update via Warp Update Online, provided the system has an internet connection. In isolated environments, Warp Update Offline can be used. It is also possible to manually update the Web Console using RPM or TARBALL packages.

Legal information

© 2024 Pandora FMS. All rights reserved.

This document cannot in any case be reproduced or modified, decompiled, disassembled, published or distributed in whole or in part, or translated to any electronic or other means without the prior written consent of Pandora FMS. All rights, titles and interests in and towards the software, services and documentation will be the exclusive property of Pandora FMS, its affiliates, and/or respective licensees.

PANDORA FMS DISCLAIMS ALL LIABILITY FOR WARRANTIES, CONDITIONS, OR OTHER TERMS, EXPRESS OR IMPLIED, LEGAL OR NOT, OVER THE DOCUMENTATION, INCLUDING WITHOUT LIMITATION THE NON-INFRINGEMENT, ACCURACY, COMPLETENESS, OR CONTENT OF ANY INFORMATION ON ANY CONTENT. IN NO EVENT SHALL PANDORA FMS, ITS SUPPLIERS OR LICENSORS BE LIABLE FOR ANY DAMAGES, WHETHER ARISING FROM CONTRACT, INJURY OR BASED ON ANY OTHER LEGAL THEORY, EVEN IF PANDORA FMS HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

All registered trademarks of Pandora FMS are the exclusive property of Pandora FMS SLU or its affiliates, registered with the United States Patent and Trademark Office (U.S. Patent and Trademark Office), as well as with the European Patent and Trademark Office. They may be registered or pending registration in other countries. All other brands mentioned herein are used for identification purposes only and are trademarks of (and may be registered trademarks) of their respective companies.