Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Zabbix — Vulnerabilities & Security Advisories 81

All 81 CVE vulnerabilities found in Zabbix, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities for the Zabbix network monitoring and management platform, specifically focusing on known weaknesses affecting its server, proxy, or agent components. It collects documented defects such as memory corruption, authentication flaws, and configuration errors, covering the historical range of advisories from the product's initial release through current versions. Readers can use this resource to track the vendor's security advisories, understand the broader weakness class patterns, and look up the complete vulnerability history for Zabbix. The aggregation highlights recurring themes in security patches, enabling security teams to identify systemic risks and prioritize remediation efforts based on historical trends. By reviewing these entries, administrators can correlate specific product versions with their associated security flaws, facilitating more informed upgrade and patch management decisions without needing to search individual vendor bulletins separately.

Vendor: Zabbix

CVE ID Title CVSS Severity Published
CVE-2026-59781 Improper validation of custom installation directories on Windows could allow installation into locations with unsafe permissions, increasing the risk of DLL sideloading. CWE-427 5.4 Medium 2026-08-18
CVE-2026-23938 Server DoS via JavaScript preprocessing or script items CWE-248 2.1 Low 2026-08-18
CVE-2026-23937 Host PSK extraction in Zabbix API CWE-203 6.0 Medium 2026-08-18
CVE-2026-23935 Use-after-free read in script item/preprocessing HttpRequest body CWE-125 6.8 Medium 2026-08-18
CVE-2026-23934 Frontend DoS via the validate.api.exists action CWE-405 5.1 Medium 2026-08-18
CVE-2026-23933 Hardcoded session key in Zabbix 7.4 CWE-259 7.7 High 2026-08-18
CVE-2026-23931 Frontend plaintext macro value enumeration via the validatate.api.exists action CWE-203 5.3 Medium 2026-08-18
CVE-2026-23930 Frontend DoS via the popup.testtriggerexpr action CWE-405 5.3 Medium 2026-08-18
CVE-2026-23929 Prototype pollution leading to stored XSS CWE-1321 8.5 High 2026-08-18
CVE-2026-1199 API and Frontend login lockout race condition CWE-362 6.9 Medium 2026-08-18
CVE-2026-23922 Email media OAuth secret leak to Super Admin CWE-522 2.1 Low 2026-08-18
CVE-2026-23928 Stored XSS vulnerability in the Item history/Plain text widget CWE-79 8.2AI High AI 2026-05-06
CVE-2026-23927 Agent 2 Oracle plugin TNS connection string injection via the 'service' parameter CWE-522 6.5AI Medium AI 2026-05-06
CVE-2026-23926 Stored XSS vulnerability in Host navigator widget maintenance tooltip CWE-79 7.3AI High AI 2026-05-06
CVE-2026-23924 Agent 2 Docker plugin arbitrary file read via Docker API injection CWE-88 6.5 - 2026-03-24
CVE-2026-23923 Unauthenticated arbitrary PHP class instantiation CWE-470 9.8 - 2026-03-24
CVE-2026-23921 Blind, read-only SQL injection in Zabbix API via sortfield parameter CWE-89 8.8 - 2026-03-24
CVE-2026-23920 Host and event action script regex validation can be bypassed in certain situations, leading to potential command injection CWE-78 8.8 - 2026-03-24
CVE-2026-23919 Insufficient isolation of JavaScript (Duktape) execution context on Zabbix Server CWE-488 2.7 - 2026-03-24
CVE-2026-23925 Unauthorized host creation via configuration.import API by low-privilege user with write permissions CWE-863 6.5 - 2026-03-06
CVE-2025-49643 Frontend DoS vulnerability due to asymmetric resource consumption CWE-405 6.5AI Medium AI 2025-12-01
CVE-2025-49642 Agent builds for AIX vulnerable to library loading hijacking CWE-426 7.8AI High AI 2025-12-01
CVE-2025-27232 Frontend arbitrary file read in oauth.authorize action CWE-918 4.9AI Medium AI 2025-12-01
CVE-2025-49641 Insufficient permission check for the problem.view.refresh action CWE-863 4.3 - 2025-10-03
CVE-2025-27237 DLL injection in Zabbix Agent and Agent 2 via OpenSSL configuration CWE-427 7.8AI High AI 2025-10-03
CVE-2025-27236 User information disclosure via api_jsonrpc.php on method user.get with param search CWE-863 4.3 - 2025-10-03
CVE-2025-27231 LDAP 'Bind password' field value can be leaked by a Zabbix Super Admin CWE-522 4.9 - 2025-10-03
CVE-2025-27240 Secondary-order SQL injection in Zabbix Server when deleting an autoregistered host CWE-89 7.2 - 2025-09-12
CVE-2025-27238 API hostprototype.get lists data to users with insufficient authorization. 5.3 - 2025-09-12
CVE-2025-27233 Zabbix Agent 2 smartctl plugin argument injection in Zabbix 6.0 and later. CWE-77 6.5 - 2025-09-12

All 81 known CVE vulnerabilities affecting Zabbix with full Chinese analysis, references, and POCs where available.