Elasticsearch
Elastic · current 9.5.2
The current version of Elasticsearch is 9.5.2 (as of 20/08/2026). patchletter checks the official source daily and emails you every new release.
Actively exploited vulnerabilities
The US cybersecurity agency CISA lists these vulnerabilities in its catalog of Known Exploited Vulnerabilities. Check your version and patch or mitigate promptly.
- CVE-2015-1427Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability
9.8 critical · over the network, without login · CISA deadline was 15 Apr 22
- CVE-2014-3120Elasticsearch Remote Code Execution Vulnerability
8.1 high · over the network, with a basic account · CISA deadline was 15 Apr 22
Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.
BSI security advisories
Advisories the German BSI (CERT-Bund) published for this product. Whether your version is affected is stated in the advisory itself.
- Elasticsearch: Mehrere Schwachstellen
WID-SEC-W-2026-2841 · 14 Aug
- Apache Tika: Schwachstelle ermöglicht Infogewinn oder Manipulation
WID-SEC-W-2025-1883 · 11 Aug
- Elasticsearch: Mehrere Schwachstellen ermöglichen DoS und die Offenlegung von Informationen
WID-SEC-W-2026-2457 · 22 Jul
- Elasticsearch: Mehrere Schwachstellen ermöglichen Denial of Service
WID-SEC-W-2026-2180 · 15 Jul
- Apache log4j: Schwachstelle ermöglicht Codeausführung
WID-SEC-W-2022-0351 · 8 Jul
Elasticsearch at a glance
Elasticsearch is a widely used search and analytics engine, often the heart of logging and search stacks. Elastic ships regular releases plus security fixes; as a data platform holding sensitive content, it deserves hardening and timely updates.
For admins updates within a major version are rolling and low-risk; major-version jumps follow a documented path with attention to deprecations and possible reindexing. Kibana tracks the same version. Regardless of patch level, the fundamentals: security features on (TLS, authentication), no open API access, and snapshots as backups — exposed Elasticsearch clusters have caused large data leaks. Check client and integration compatibility across versions. Following Elastic's licensing changes, some run the OpenSearch fork — if so, follow its line. Track the version and its support window.
Support cycles (endoflife.date)
| Cycle | Latest version | Status |
|---|---|---|
| 9.5 | 9.5.2 | supported |
| 9.4 | 9.4.5 | supported |
| 9.3 | 9.3.8 | End of Life |
| 9.2 | 9.2.8 | End of Life |
| 9.1 | 9.1.10 | End of Life |
| 8.19 | 8.19.20 | EOL 15 Jul 27 |
| 8.18 | 8.18.8 | End of Life |
| 9.0 | 9.0.8 | End of Life |
Version history & changelog · as detected by patchletter
| Version | Channel | Date | Notes |
|---|---|---|---|
| 9.5.2 | STABLE | 20/08/2026 | Release notes → |
| 9.5.1 | STABLE | 11/08/2026 | Release notes → |
| 9.4.5 | STABLE | 11/08/2026 | Release notes → |
| 9.4.4 | STABLE | 15/07/2026 | Release notes → |
| 9.4.3 | STABLE | 25/06/2026 | Release notes → |
Frequently asked questions
- What is the latest version of Elasticsearch?
- Elasticsearch 9.5.2, released 20/08/2026. patchletter checks the vendor's official source daily for new releases.
- Where can I find the Elasticsearch release notes?
- The version history above links to the vendor's official release notes where the vendor publishes them. patchletter deliberately stores no vendor full texts.
- How do I get notified about new Elasticsearch updates?
- Free by email: patchletter reports every new release — instantly or bundled as a digest. Unsubscribe anytime with one click.
Never miss a Elasticsearch update
We check the source daily and email you — instantly or as a digest. Free, one-click unsubscribe.
Watch ElasticsearchEmbed this badge
Shows the current Elasticsearch version and updates itself. Free to use, no account needed.
[](https://patchletter.com/en/software/elasticsearch)https://patchletter.com/badge/elasticsearch.svgAlso available: ?v=eol (end of support) and ?v=cve (actively exploited).