The current version of Cacti is release/1.2.31 (as of 16/06/2026). patchletter checks the official source daily and emails you new releases.
Actively exploited vulnerabilities
The US cybersecurity agency CISA lists this vulnerability in its catalog of Known Exploited Vulnerabilities. What CISA does not carry does not appear in this list — even where it is being exploited.
- CVE-2022-46169Cacti Command Injection Vulnerability
9.8 critical · over the network, without login · CISA deadline was 9 Mar 23
Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.
BSI security advisories
Advisories the German BSI (CERT-Bund) published for this product. Whether your version is affected is stated in the advisory itself.
- Cacti: Mehrere Schwachstellen
WID-SEC-W-2026-1931 · 12 Aug
- Cacti: Schwachstelle ermöglicht SQL-Injection
WID-SEC-W-2026-2684 · 6 Aug
- Cacti: Schwachstelle ermöglicht Offenlegung von Informationen
WID-SEC-W-2026-2018 · 22 Jun
Cacti at a glance
Cacti is a long-established open-source network monitoring and graphing tool built on RRDtool, common for bandwidth and device graphing. Cacti ships regular releases plus coordinated security fixes; as a web application with network visibility and device credentials, hardening and prompt patching matter.
For admins Cacti has had serious, actively exploited security vulnerabilities (including remote code execution), so apply security releases promptly and never expose it to the internet — keep it strictly on the management network behind authentication. Updates run database changes — back up the database and the RRD files first, and keep the underlying PHP and database supported. Plugins extend Cacti and carry their own risk — keep them minimal and current. After updating, verify that polling and graphs still work. Because its past CVEs have been weaponized, treat Cacti's advisories with particular seriousness. Track the version and its support status; patchletter surfaces new Cacti releases.
Version history & changelog · as detected by patchletter
| Version | Channel | Date | Notes |
|---|---|---|---|
| release/1.2.31 | STABLE | 16/06/2026 | Release notes → |
| release/1.2.30 | STABLE | 23/03/2025 | Release notes → |
| release/1.2.29 | STABLE | 02/02/2025 | Release notes → |
| release/1.2.28 | STABLE | 07/10/2024 | Release notes → |
| release/1.2.27 | STABLE | 12/05/2024 | Release notes → |
| release/1.2.26 | STABLE | 24/12/2023 | Release notes → |
| release/1.2.25 | STABLE | 05/09/2023 | Release notes → |
| release/1.2.24 | STABLE | 27/02/2023 | Release notes → |
| release/1.2.23 | STABLE | 02/01/2023 | Release notes → |
| release/1.2.22 | STABLE | 15/08/2022 | Release notes → |
| release/1.2.21 | STABLE | 19/05/2022 | Release notes → |
| release/1.2.20 | STABLE | 06/04/2022 | Release notes → |
| release/1.2.19 | STABLE | 29/10/2021 | Release notes → |
| release/1.2.18 | STABLE | 04/07/2021 | Release notes → |
| release/1.2.17 | STABLE | 03/05/2021 | Release notes → |
| release/1.2.16 | STABLE | 30/11/2020 | Release notes → |
| release/1.2.15 | STABLE | 02/11/2020 | Release notes → |
| release/1.2.14 | STABLE | 03/08/2020 | Release notes → |
| release/1.2.13 | STABLE | 03/08/2020 | Release notes → |
| release/1.2.12 | STABLE | 03/08/2020 | Release notes → |
| release/1.2.11 | STABLE | 07/04/2020 | Release notes → |
| release/1.2.10 | STABLE | 28/03/2020 | Release notes → |
| release/1.2.9 | STABLE | 28/03/2020 | Release notes → |
| release/1.2.8 | STABLE | 09/12/2019 | Release notes → |
| release/1.2.7 | STABLE | 29/09/2019 | Release notes → |
| release/1.2.6 | STABLE | 02/09/2019 | Release notes → |
| release/1.2.5 | STABLE | 02/09/2019 | Release notes → |
| release/1.2.4 | STABLE | 07/06/2019 | Release notes → |
Frequently asked questions
- What is the latest version of Cacti?
- Cacti release/1.2.31, released 16/06/2026. patchletter checks the vendor's official source daily for new releases.
- Where can I find the Cacti release notes?
- The version history above links to the vendor's official release notes where the vendor publishes them. patchletter deliberately stores no vendor full texts.
- How do I get notified about new Cacti updates?
- Tick Cacti off in the catalogue and leave your address. From then on new versions go out by email — one at a time, or bundled in the daily or weekly digest.
An email as soon as a new Cacti version ships
We reconcile the vendor source daily. When a new version appears, it lands in your inbox right away or bundled as a digest. The update email is free and ends with one click. Alerts about vulnerabilities and end of support are part of patchletter Pro.
Embed this badge
The badge shows the current Cacti version and keeps it up to date. Anyone may embed it, no account needed.
[](https://patchletter.com/en/software/cacti)https://patchletter.com/badge/cacti.svgAlso available: ?v=eol (end of support) and ?v=cve (actively exploited).