VulnSea

Zabbix has 27 CVEs on record between 2025 and 2026. Disclosure cadence is accelerating: 17 in the last 90 days against 3 in the 90 before. The busiest recent month was August 2026 with 11. The median CVSS is 6.0 (medium), with 1 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-405 (3) and CWE-79 (3). Most affected products: Zabbix (25), frontend (2).

CVEs per month

Last 12 months, by publish date

111201020304050607080910
Exploited share
0% vs 1% corpus
Median CVSS
6.0
Publish → KEV
—
Last 90 days
17 prev 3

Products

  • Zabbix 25
  • frontend 2
27
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

Zabbix vulnerabilities

CVEs affecting Zabbix, newest first. Open any entry for full detail, references, and exploit status.

27 CVEsRSS

CVE-2026-59788Medium· 5.6
today

The email media type OAuth form passes the Authorization endpoint value to window.open() without validating the URL scheme, so a javascript: URL is executed in the browser

The email media type OAuth form passes the Authorization endpoint value to window.open() without validating the URL scheme, so a javascript: URL is executed in the browser. This means a crafted media type configuration, deliverable as an…

▾ SunlitZabbix · Zabbixvia NVD
CVE-2026-59787Medium· 5.3
today

The Perl SNMP trap receiver script shipped with Zabbix does not properly neutralize the ZBXTRAP record delimiter in trap content

The Perl SNMP trap receiver script shipped with Zabbix does not properly neutralize the ZBXTRAP record delimiter in trap content. This means someone able to send SNMP traps can inject a record targeting another host, resulting in a loss …

▾ SunlitZabbix · Zabbixvia NVD
CVE-2026-59786Medium· 6.9
today

Zabbix Server and Proxy accept the active agent heartbeat message regardless of the configured PSK or certificate authentication

Zabbix Server and Proxy accept the active agent heartbeat message regardless of the configured PSK or certificate authentication. This means someone with access to the Zabbix trapper port can report an arbitrary host using an active agen…

▾ SunlitZabbix · Zabbixvia NVD
CVE-2026-59785Medium· 5.1
today

Host search in Frontend allows filtering by fields that are not displayed, including stored IPMI and PSK credentials

Host search in Frontend allows filtering by fields that are not displayed, including stored IPMI and PSK credentials. A user with read access can guess a credential and see from the search result whether the guess was right, letting them…

▾ SunlitZabbix · Zabbixvia NVD
CVE-2026-59783Low· 2.3
today

The Zabbix Server/Proxy has a vulnerability where binary items can crash the Server/Proxy on certain NULL byte input leading to potential loss of availability

The Zabbix Server/Proxy has a vulnerability where binary items can crash the Server/Proxy on certain NULL byte input leading to potential loss of availability. This only affects deployments where MySQL/MariaDB database is used as the Zab…

▾ SunlitZabbix · Zabbixvia NVD
CVE-2026-59782Medium· 6.9
today

The JavaScript preprocessing (Duktape) engine on Zabbix server has a vulnerability where a limited administrator is able to read raw heap data potentially resulting in leaked data from other running preprocessors not available to said ad…

The JavaScript preprocessing (Duktape) engine on Zabbix server has a vulnerability where a limited administrator is able to read raw heap data potentially resulting in leaked data from other running preprocessors not available to said ad…

▾ SunlitZabbix · Zabbixvia NVD
CVE-2026-59781High· 7.8
1mo ago

When Zabbix Agent was installed on Windows into a custom installation directory, the installer did not verify whether the selected directory had secure access permissions

When Zabbix Agent was installed on Windows into a custom installation directory, the installer did not verify whether the selected directory had secure access permissions. If the target directory allowed unauthorized users to modify its …

▾ Twilightzabbix · zabbixEPSS 0.12%via NVD
CVE-2026-23938Medium· 4.9
1mo ago

An authenticated administrator is able to crash Zabbix server or proxy by creating specifically crafted preprocessing/script item JavaScript scripts, leading to potential denial of service.

An authenticated administrator is able to crash Zabbix server or proxy by creating specifically crafted preprocessing/script item JavaScript scripts, leading to potential denial of service.

▾ Sunlitzabbix · zabbixEPSS 0.35%via NVD
CVE-2026-23934Medium· 6.5
1mo ago

An authenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend validate.api.exists action, leading to potential denial of service.

An authenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend validate.api.exists action, leading to potential denial of service.

▾ Sunlitzabbix · zabbixEPSS 0.36%via NVD
CVE-2026-23933Critical· 9.1
1mo ago

In Zabbix 7.4 the cryptographic key used for signing Frontend sessions has been erroneously written to the database seed

In Zabbix 7.4 the cryptographic key used for signing Frontend sessions has been erroneously written to the database seed. Currently the only known exploitation scenario is for deployments that utilize both - SAML authentication and guest…

▾ Midnightzabbix · zabbixEPSS 0.36%via NVD
CVE-2026-23931Medium· 4.3⚖ disputed
1mo ago

The frontend validatate.api.exists action can be exploited by authenticated users to extract plaintext user macro values leading to potential loss of confidentiality.

The frontend validatate.api.exists action can be exploited by authenticated users to extract plaintext user macro values leading to potential loss of confidentiality.

▾ Sunlitzabbix · zabbixEPSS 0.23%via NVD
CVE-2026-23937Medium· 6.5
1mo ago

The Zabbix API host.get action can be exploited by authenticated users to extract a host's PSK key leading to potential loss of data integrity.

The Zabbix API host.get action can be exploited by authenticated users to extract a host's PSK key leading to potential loss of data integrity.

▾ Sunlitzabbix · zabbixEPSS 0.27%via NVD
CVE-2026-23935Medium· 4.9
1mo ago

A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item/preprocessing (JavaScript) HttpRequest logic, leading to potential confidentiality loss.

A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item/preprocessing (JavaScript) HttpRequest logic, leading to potential confidentiality loss.

▾ Sunlitzabbix · zabbixEPSS 0.34%via NVD
CVE-2026-23930High· 7.5
1mo ago

An unauthenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend popup.testtriggerexpr action, leading to potential denial of service.

An unauthenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend popup.testtriggerexpr action, leading to potential denial of service.

▾ Twilightzabbix · zabbixEPSS 0.36%via NVD
CVE-2026-23929Medium· 5.4
1mo ago

Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps

Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter processing was not filtering dangerous properties like __proto__, combined with jQuery's unsafe element creation that trave…

▾ Sunlitzabbix · zabbixEPSS 0.18%via NVD
CVE-2026-23922Medium· 4.9
1mo ago

The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can leak it by setting a malicious 'Token endpoint'

The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can leak it by setting a malicious 'Token endpoint'. Changes were made to reset the client secret upon changing the token endpoint.

▾ Sunlitzabbix · zabbixEPSS 0.27%via NVD
CVE-2026-1199Low· 3.7
1mo ago

Zabbix API and Frontend login lockout mechanism has a flaw where several unsuccessful login requests are not properly counted towards the block counter if sent simultaneously, potentially allowing for more password guesses than intended.

Zabbix API and Frontend login lockout mechanism has a flaw where several unsuccessful login requests are not properly counted towards the block counter if sent simultaneously, potentially allowing for more password guesses than intended.

▾ Sunlitzabbix · zabbixEPSS 0.17%via NVD
CVE-2026-23928Medium· 6.8
5mo ago

The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled

The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized actions depending on which user opens a da…

▾ Sunlitzabbix · zabbixEPSS 0.26%via NVD
CVE-2026-23927Medium· 6.5
5mo ago

A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter

A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead to Agent 2 connecting to an attacker-controlled server and leaking Oracle database credentials if they are saved in a…

▾ Sunlitzabbix · zabbixEPSS 0.22%via NVD
CVE-2026-23926Medium· 6.8
5mo ago

An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget

An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to…

▾ Sunlitzabbix · zabbixEPSS 0.26%via NVD
CVE-2026-23924Medium· 4.9
6mo ago

Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding them to the Docker daemon

Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding them to the Docker daemon. An attacker capable of invoking Agent 2 can read arbitrary files from running Docker containers by …

▾ Sunlitzabbix · zabbixEPSS 0.23%via NVD
CVE-2026-23919Medium· 6.0
6mo ago

For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks)

For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks). This can lead to confidentiality loss where a regular (non-super) Zabbix administrator leaks data…

▾ Sunlitzabbix · zabbixEPSS 0.24%via NVD
CVE-2026-23923Medium· 5.3
6mo ago

An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes

An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The impact depends on environment setup but appears limited at this time.

▾ Sunlitzabbix · zabbixEPSS 0.27%via NVD
CVE-2026-23921High· 8.8PoC
6mo ago

A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter

A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter. Although query results are not returned dire…

▾ Midnightzabbix · zabbixEPSS 3.9%via NVD
CVE-2026-23920High· 8.8
6mo ago

Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode

Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode. If ^ and $ anchors are used in user input validation, an injected newline lets authenticated users bypass…

▾ Twilightzabbix · zabbixEPSS 0.30%via NVD
CVE-2025-49643Medium· 6.5
10mo ago

An authenticated Zabbix user (including Guest) is able to cause disproportionate CPU load on the webserver by sending specially crafted parameters to /imgstore.php, leading to potential denial of service.

An authenticated Zabbix user (including Guest) is able to cause disproportionate CPU load on the webserver by sending specially crafted parameters to /imgstore.php, leading to potential denial of service.

▾ Sunlitzabbix · frontendEPSS 0.34%via NVD
CVE-2025-27232Medium· 4.9
10mo ago

An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary files from the webserver leading to potential confidentiality loss.

An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary files from the webserver leading to potential confidentiality loss.

▾ Sunlitzabbix · frontendEPSS 0.29%via NVD
Zabbix vulnerabilities (CVEs) · VulnSea