The current version of Grafana is 13.2.3 (as of 29/09/2026). patchletter checks the official source daily and emails you new releases.
Actively exploited vulnerabilities
The US cybersecurity agency CISA lists these vulnerabilities in its catalog of Known Exploited Vulnerabilities. What CISA does not carry does not appear in this list — even where it is being exploited.
- CVE-2021-43798Grafana Path Traversal Vulnerability
7.5 high · over the network, without login · CISA deadline was 30 Oct 25
- CVE-2021-39226Grafana Authentication Bypass Vulnerability
7.3 high · over the network, without login · CISA deadline was 15 Sept 22
Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.
BSI security advisories
Advisories the German BSI (CERT-Bund) published for this product. Whether your version is affected is stated in the advisory itself.
- Grafana: Mehrere Schwachstellen
WID-SEC-W-2026-0224 · 9 Oct
- Grafana: Mehrere Schwachstellen
WID-SEC-W-2026-1546 · 7 Oct
- Grafana: Schwachstelle ermöglicht Cross-Site Scripting
WID-SEC-W-2026-3474 · 6 Oct
- Grafana: Schwachstelle ermöglicht Offenlegung von Informationen
WID-SEC-W-2026-3652 · 6 Oct
- Grafana: Mehrere Schwachstellen
WID-SEC-W-2026-3675 · 6 Oct
- Grafana: Schwachstelle ermöglicht Codeausführung
WID-SEC-W-2026-3450 · 18 Sept
- Grafana: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen und Offenlegung von Informationen
WID-SEC-W-2026-3355 · 15 Sept
- Grafana: Mehrere Schwachstellen
WID-SEC-W-2026-2289 · 15 Sept
Grafana at a glance
Grafana is the de-facto standard for observability dashboards, visualizing metrics, logs and traces from many data sources. Grafana Labs ships frequent releases plus security fixes; as a dashboard often reachable from the network and holding data-source credentials, it deserves prompt updates.
For admins updates are usually straightforward (swap the binary/container); larger jumps can bring configuration and plugin changes — read the upgrade notes and back up the database first. Plugins have their own cycles. Grafana belongs behind authentication (ideally SSO) and off the open internet, since a dashboard can expose a lot about the infrastructure and its data sources. Several Grafana advisories concerned authentication and data-source proxying, so apply security releases promptly. Track the version and its support status.
Support cycles (endoflife.date)
| Cycle | Latest version | Status |
|---|---|---|
| 13.2 | 13.2.3 | EOL 18 May 27 |
| 13.1 | 13.1.7 | EOL 20 Mar 27 |
| 13.0 | 13.0.10 | EOL 9 Jan 27 |
| 12.4 | 12.4.12 | EOL 24 May 27 |
| 12.3 | 12.3.11 | End of Life |
| 12.2 | 12.2.10 | End of Life |
| 12.1 | 12.1.10+security-01 | End of Life |
| 12.0 | 12.0.10 | End of Life |
Version history & changelog · as detected by patchletter
| Version | Channel | Date | Notes |
|---|---|---|---|
| 13.2.3 | STABLE | 29/09/2026 | Release notes → |
| 13.2.2 | STABLE | 15/09/2026 | – |
| 13.2.1 | STABLE | 01/09/2026 | – |
| 13.2.0 | STABLE | 18/08/2026 | Release notes → |
| 13.1.4 | STABLE | 18/08/2026 | – |
| 13.1.3 | STABLE | 07/08/2026 | Release notes → |
| 13.1.2 | STABLE | 04/08/2026 | – |
| 13.1.1 | STABLE | 21/07/2026 | Release notes → |
| 13.1.0 | STABLE | 01/07/2026 | Release notes → |
| 13.0.4 | STABLE | 21/07/2026 | Release notes → |
| 13.0.3 | STABLE | 23/06/2026 | Release notes → |
| 13.0.2 | STABLE | 09/06/2026 | Release notes → |
| 13.0.1 | STABLE | 17/04/2026 | Release notes → |
| 13.0.1+security-01 | STABLE | 12/05/2026 | Release notes → |
| 12.4.6 | STABLE | 21/07/2026 | Release notes → |
| 12.4.5 | STABLE | 23/06/2026 | Release notes → |
| 12.4.4 | STABLE | 09/06/2026 | Release notes → |
| 12.4.3 | STABLE | 14/04/2026 | Release notes → |
| 12.4.3+security-02 | STABLE | 12/05/2026 | Release notes → |
| 12.4.2 | STABLE | 25/03/2026 | Release notes → |
| 12.4.1 | STABLE | 09/03/2026 | Release notes → |
| 12.4.0 | STABLE | 25/02/2026 | Release notes → |
| 12.3.9 | STABLE | 21/07/2026 | Release notes → |
| 12.3.8 | STABLE | 23/06/2026 | Release notes → |
| 12.3.7 | STABLE | 09/06/2026 | Release notes → |
| 12.3.6 | STABLE | 26/03/2026 | Release notes → |
| 12.3.6+security-04 | STABLE | 12/05/2026 | Release notes → |
| 12.3.6+security-01 | STABLE | 26/03/2026 | Release notes → |
| 12.3.5 | STABLE | 09/03/2026 | Release notes → |
| 12.3.4 | STABLE | 24/02/2026 | Release notes → |
| 12.3.3 | STABLE | 12/02/2026 | Release notes → |
| 12.3.2 | STABLE | 27/01/2026 | Release notes → |
| 12.3.2+security-01 | STABLE | 11/02/2026 | Release notes → |
| 12.3.1 | STABLE | 16/12/2025 | Release notes → |
| 12.3.0 | STABLE | 19/11/2025 | Release notes → |
| 12.2.10 | STABLE | 23/06/2026 | Release notes → |
| 12.2.9 | STABLE | 09/06/2026 | Release notes → |
| 12.2.8 | STABLE | 26/03/2026 | Release notes → |
| 12.2.8+security-04 | STABLE | 12/05/2026 | Release notes → |
| 12.2.8+security-01 | STABLE | 25/03/2026 | Release notes → |
| 12.2.7 | STABLE | 09/03/2026 | Release notes → |
| 12.2.6 | STABLE | 24/02/2026 | Release notes → |
| 12.2.5 | STABLE | 12/02/2026 | Release notes → |
| 12.2.4 | STABLE | 27/01/2026 | Release notes → |
| 12.2.4+security-01 | STABLE | 11/02/2026 | Release notes → |
| 12.2.3 | STABLE | 16/12/2025 | Release notes → |
| 12.2.2 | STABLE | 19/11/2025 | Release notes → |
| 12.2.1 | STABLE | 21/10/2025 | Release notes → |
| 12.2.1+security-01 | STABLE | 19/11/2025 | Release notes → |
| 12.2.0 | STABLE | 24/09/2025 | Release notes → |
Frequently asked questions
- What is the latest version of Grafana?
- Grafana 13.2.3, released 29/09/2026. patchletter checks the vendor's official source daily for new releases.
- Where can I find the Grafana release notes?
- The version history above links to the vendor's official release notes where the vendor publishes them. patchletter deliberately stores no vendor full texts.
- How do I get notified about new Grafana updates?
- Tick Grafana off in the catalogue and leave your address. From then on new versions go out by email — one at a time, or bundled in the daily or weekly digest.
An email as soon as a new Grafana version ships
We reconcile the vendor source daily. When a new version appears, it lands in your inbox right away or bundled as a digest. The update email is free and ends with one click. Alerts about vulnerabilities and end of support are part of patchletter Pro.
Embed this badge
The badge shows the current Grafana version and keeps it up to date. Anyone may embed it, no account needed.
[](https://patchletter.com/en/software/grafana)https://patchletter.com/badge/grafana.svgAlso available: ?v=eol (end of support) and ?v=cve (actively exploited).