Elasticsearch

Elastic · current 9.5.5

Are you Elastic? Claim this page

The current version of Elasticsearch is 9.5.5 (as of 06/10/2026). patchletter checks the official source daily and emails you new releases.

Actively exploited vulnerabilities

The US cybersecurity agency CISA lists these vulnerabilities in its catalog of Known Exploited Vulnerabilities. What CISA does not carry does not appear in this list — even where it is being exploited.

  • CVE-2015-1427Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability

    9.8 critical · over the network, without login · CISA deadline was 15 Apr 22

  • CVE-2014-3120Elasticsearch Remote Code Execution Vulnerability

    8.1 high · over the network, with a basic account · CISA deadline was 15 Apr 22

Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.

BSI security advisories

Advisories the German BSI (CERT-Bund) published for this product. Whether your version is affected is stated in the advisory itself.

All BSI advisories →

Elasticsearch at a glance

Elasticsearch is a widely used search and analytics engine, often the heart of logging and search stacks. Elastic ships regular releases plus security fixes; as a data platform holding sensitive content, it deserves hardening and timely updates.

For admins updates within a major version are rolling and low-risk; major-version jumps follow a documented path with attention to deprecations and possible reindexing. Kibana tracks the same version. Regardless of patch level, the fundamentals: security features on (TLS, authentication), no open API access, and snapshots as backups — exposed Elasticsearch clusters have caused large data leaks. Check client and integration compatibility across versions. Following Elastic's licensing changes, some run the OpenSearch fork — if so, follow its line. Track the version and its support window.

Support cycles (endoflife.date)

CycleLatest versionStatus
9.59.5.5supported
9.49.4.8supported
9.39.3.8End of Life
9.29.2.8End of Life
9.19.1.10End of Life
8.198.19.23EOL 15 Jul 27
8.188.18.8End of Life
9.09.0.8End of Life

Version history & changelog · as detected by patchletter

VersionChannelDateNotes
9.5.5STABLE06/10/2026Release notes →
9.5.4STABLE15/09/2026Release notes →
9.5.3STABLE03/09/2026Release notes →
9.5.2STABLE20/08/2026Release notes →
9.5.1STABLE11/08/2026Release notes →
9.4.5STABLE11/08/2026Release notes →
9.4.4STABLE15/07/2026Release notes →
9.4.3STABLE25/06/2026Release notes →

Frequently asked questions

What is the latest version of Elasticsearch?
Elasticsearch 9.5.5, released 06/10/2026. patchletter checks the vendor's official source daily for new releases.
Where can I find the Elasticsearch release notes?
The version history above links to the vendor's official release notes where the vendor publishes them. patchletter deliberately stores no vendor full texts.
How do I get notified about new Elasticsearch updates?
Tick Elasticsearch off in the catalogue and leave your address. From then on new versions go out by email — one at a time, or bundled in the daily or weekly digest.

An email as soon as a new Elasticsearch version ships

We reconcile the vendor source daily. When a new version appears, it lands in your inbox right away or bundled as a digest. The update email is free and ends with one click. Alerts about vulnerabilities and end of support are part of patchletter Pro.

Embed this badge

The badge shows the current Elasticsearch version and keeps it up to date. Anyone may embed it, no account needed.

Elasticsearch badge
[![Elasticsearch](https://patchletter.com/badge/elasticsearch.svg)](https://patchletter.com/en/software/elasticsearch)
https://patchletter.com/badge/elasticsearch.svg

Also available: ?v=eol (end of support) and ?v=cve (actively exploited).

Related tools in Servers & Databases