Version: Pandora FMS 777 LTSRelease date: February 24, 2026
LTS Patches
We only release patches for Long Time Support (LTS) versions, except for some particular cases where we do so for Feature Release (FR) versions.
Security patches are developed as soon as possible after the vulnerability is detected. Patches for LTS versions usually include critical-bug troubleshooting and solutions to security problems.
Bug fixes
| FIX LTS# | GitLab# | Description |
|---|---|---|
|
17919 |
14185, 17372 |
In Dashboards with event widgets, the visual style has been refined and now displays and maintains all elements in the same way. |
|
18079 |
17586 |
The process for saving NCM agents has been corrected. |
|
18267 |
17717 |
The display of IP addresses and MAC addresses has been fixed in the SNMP agent interfaces. |
|
18269 |
17495 |
The display of regular expressions in external monitoring policy alerts in the Web Console has been corrected. |
|
18270 |
17453 |
The filtering by alert status was corrected in the agent. |
|
18357 |
18348 |
In Command Center, Linked Visual Consoles, it has been corrected that when elements are disabled, they no longer affect higher levels. |
|
18525 |
18452 |
The monthly SLA report (PDF file) has been fixed for all languages other than English. |
|
18597 |
18596 |
Added exception routine for the “Data_in_files” module of the PFMS self-monitoring agent. |
|
18780 |
14200 |
Corrected “Select All” behavior for agents and modules in Mass Module Editing. |
|
18821, 19735 |
18820 |
Time thresholds applied to alerts through monitoring policies have been corrected. |
|
18883 |
18569 |
The “_start_date_” and “_end_date_” macros in reports were corrected to return the correct values. |
|
18887 |
18851 |
Fixed module event report. |
|
19084 |
18042 |
The count of agents for license purposes has been corrected. |
|
19085 |
14333, 19046 |
In the bulk editing of modules, the display of agents whose modules were selected first has been fixed. |
|
19100 |
18040 |
In event alerts, rule applications whose conditions include tag values have been fixed. |
|
19543 |
18191 |
Fixed the inclusion of IP addresses when creating modules using the SNMP interface wizard. |
|
19556 |
16132 |
The creation of users and their logins in the Web Console have been fixed when SAML (user ID attribute field) is used as the authentication method in Pandora FMS. |
Improvements and small changes
| FIX LTS# | GitLab# | Description |
|---|---|---|
|
18268 |
16083 |
In string-type modules, their display has been improved by the Web Console, taking into account whether the check result has more than 200 characters and whether it contains line breaks. |
Known Changes and Limitations
| FIX LTS# | GitLab# | Description |
|---|---|---|
|
18342 (23301, 23343) |
N/A |
The links to the old PFMS library have been replaced with a new notice directing users to the new website. |
|
18696 |
18695 |
The “Allow non-consecutive patches” token being disabled also allows you to upgrade to the next LTS version. |
Fixed vulnerabilities
See our Common Vulnerabilities and Exposures (CVE®) list.
| FIX LTS# | GitLab# | Description |
|---|---|---|
|
19199 CVE-2026-34188 Special thanks to: Pedro J. Núñez-Cacho Fuentes |
19178 |
The arbitrary SQL injection vulnerability involving access to custom event responses has been fixed. |
|
19200 CVE-2026-34187 Special thanks to: Pedro J. Núñez-Cacho Fuentes |
19177 |
Numeric variable types were updated to prevent SQL injection in AJAX. |
|
19201 CVE-2026-34186 Special thanks to: Pedro J. Núñez-Cacho Fuentes |
19176 |
The arbitrary SQL injection vulnerability involving access to custom agent fields has been fixed. |
|
19202 CVE-2026-30813 Special thanks to: Pedro J. Núñez-Cacho Fuentes |
19174 |
A vulnerability involving the injection of arbitrary SQL code through access to and queries of modules in the Dashboards feature has been fixed. |
|
19203 CVE-2026-30812 Special thanks to: Pedro J. Núñez-Cacho Fuentes |
19173 |
A vulnerability involving unauthorized code injection via event comments (XSS) has been fixed. |
|
19204 CVE-2026-30811 Special thanks to: Pedro J. Núñez-Cacho Fuentes |
19172 |
The leftover files and functions from discontinued features—which had allowed access to important and sensitive information—were permanently deleted. |
|
19205 CVE-2026-30810 Special thanks to: Pedro J. Núñez-Cacho Fuentes |
19171 |
The ability to execute PFMS 1.0 API commands via the web console was restricted to superadmin users (additional security measures were also implemented). |
|
19206 CVE-2026-30809 Special thanks to: Pedro J. Núñez-Cacho Fuentes |
19170 |
Fixed a command injection vulnerability in web module debugging. |
|
19207 CVE-2026-30808 Special thanks to: Pedro J. Núñez-Cacho Fuentes |
19169 Related: 26, 14673 |
Added regeneration of the PHPSESSID cookie after a user successfully logs in to the PFMS Web Console. |
|
19208 CVE-2026-30807 Special thanks to: Pedro J. Núñez-Cacho Fuentes |
19168, 19163 |
Fixed CSRF validation on PFMS Web Console extension pages. |
|
19209 CVE-2026-30806 Special thanks to: Pedro J. Núñez-Cacho Fuentes |
19167 |
The command injection via WHOIS into the operating system has been fixed. |
|
19211 CVE-2026-30805 Special thanks to: Pedro J. Núñez-Cacho Fuentes |
19166, 19740 |
Random password generation has been added to the PFMS API upon installation. For existing installations, a persistent warning has been added until the password is changed. |
|
19212 CVE-2026-30804 Special thanks to: Pedro J. Núñez-Cacho Fuentes |
19163 |
Registration, integration and validation of extensions for the PFMS Web Console are fixed. |
19213 |
18688 |
The search for text strings in custom fields (such as password fields) has been removed. |








