# CVE-2026-40941

> Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a package import signature validation bypass allows which allows self-signed packages. This issue has been fixed in version 1.2.31.

- **CVSS:** 7.1
- **EPSS:** 0.2%
- **CWE:** CWE-347

Canonical: https://intel.threadlinqs.com/cve/CVE-2026-40941
Full threat coverage + IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
