Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Zabbix — Vulnerabilities & Security Advisories 94

Browse all 94 CVE security advisories affecting Zabbix. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Zabbix is an enterprise-class open-source monitoring solution designed for real-time observation of IT infrastructure, including servers, networks, and applications. Its architecture relies on a central server, database, and agents to collect performance metrics and trigger alerts. Historically, the platform has been associated with eighty-three recorded Common Vulnerabilities and Exposures (CVEs), predominantly involving SQL injection, cross-site scripting, and remote code execution flaws. These issues often stem from insufficient input validation within the web interface or improper access controls in API endpoints. While the software itself is robust, its complexity in deployment can introduce configuration weaknesses. Notable incidents have highlighted risks related to privilege escalation and unauthorized data access, emphasizing the need for rigorous patch management. Security audits frequently recommend disabling unused modules and enforcing strict network segmentation to mitigate potential exploitation vectors inherent in its extensive feature set.

CVE IDTitleCVSSSeverityPublished
CVE-2026-59781 Improper validation of custom installation directories on Windows could allow installation into locations with unsafe permissions, increasing the risk of DLL sideloading. — ZabbixCWE-427 5.4 Medium2026-08-18
CVE-2026-23938 Server DoS via JavaScript preprocessing or script items — ZabbixCWE-248 2.1 Low2026-08-18
CVE-2026-23937 Host PSK extraction in Zabbix API — ZabbixCWE-203 6.0 Medium2026-08-18
CVE-2026-23935 Use-after-free read in script item/preprocessing HttpRequest body — ZabbixCWE-125 6.8 Medium2026-08-18
CVE-2026-23934 Frontend DoS via the validate.api.exists action — ZabbixCWE-405 5.1 Medium2026-08-18
CVE-2026-23933 Hardcoded session key in Zabbix 7.4 — ZabbixCWE-259 7.7 High2026-08-18
CVE-2026-23931 Frontend plaintext macro value enumeration via the validatate.api.exists action — ZabbixCWE-203 5.3 Medium2026-08-18
CVE-2026-23930 Frontend DoS via the popup.testtriggerexpr action — ZabbixCWE-405 5.3 Medium2026-08-18
CVE-2026-23929 Prototype pollution leading to stored XSS — ZabbixCWE-1321 8.5 High2026-08-18
CVE-2026-1199 API and Frontend login lockout race condition — ZabbixCWE-362 6.9 Medium2026-08-18
CVE-2026-23922 Email media OAuth secret leak to Super Admin — ZabbixCWE-522 2.1 Low2026-08-18
CVE-2026-23928 Stored XSS vulnerability in the Item history/Plain text widget — ZabbixCWE-79 8.2AIHighAI2026-05-06
CVE-2026-23927 Agent 2 Oracle plugin TNS connection string injection via the 'service' parameter — ZabbixCWE-522 6.5AIMediumAI2026-05-06
CVE-2026-23926 Stored XSS vulnerability in Host navigator widget maintenance tooltip — ZabbixCWE-79 7.3AIHighAI2026-05-06
CVE-2026-23924 Agent 2 Docker plugin arbitrary file read via Docker API injection — ZabbixCWE-88 6.5 -2026-03-24
CVE-2026-23923 Unauthenticated arbitrary PHP class instantiation — ZabbixCWE-470 9.8 -2026-03-24
CVE-2026-23921 Blind, read-only SQL injection in Zabbix API via sortfield parameter — ZabbixCWE-89 8.8 -2026-03-24
CVE-2026-23920 Host and event action script regex validation can be bypassed in certain situations, leading to potential command injection — ZabbixCWE-78 8.8 -2026-03-24
CVE-2026-23919 Insufficient isolation of JavaScript (Duktape) execution context on Zabbix Server — ZabbixCWE-488 2.7 -2026-03-24
CVE-2026-23925 Unauthorized host creation via configuration.import API by low-privilege user with write permissions — ZabbixCWE-863 6.5 -2026-03-06
CVE-2025-49643 Frontend DoS vulnerability due to asymmetric resource consumption — ZabbixCWE-405 6.5AIMediumAI2025-12-01
CVE-2025-49642 Agent builds for AIX vulnerable to library loading hijacking — ZabbixCWE-426 7.8AIHighAI2025-12-01
CVE-2025-27232 Frontend arbitrary file read in oauth.authorize action — ZabbixCWE-918 4.9AIMediumAI2025-12-01
CVE-2025-49641 Insufficient permission check for the problem.view.refresh action — ZabbixCWE-863 4.3 -2025-10-03
CVE-2025-27237 DLL injection in Zabbix Agent and Agent 2 via OpenSSL configuration — ZabbixCWE-427 7.8AIHighAI2025-10-03
CVE-2025-27236 User information disclosure via api_jsonrpc.php on method user.get with param search — ZabbixCWE-863 4.3 -2025-10-03
CVE-2025-27231 LDAP 'Bind password' field value can be leaked by a Zabbix Super Admin — ZabbixCWE-522 4.9 -2025-10-03
CVE-2025-27240 Secondary-order SQL injection in Zabbix Server when deleting an autoregistered host — ZabbixCWE-89 7.2 -2025-09-12
CVE-2025-27238 API hostprototype.get lists data to users with insufficient authorization. — Zabbix 5.3 -2025-09-12
CVE-2025-27233 Zabbix Agent 2 smartctl plugin argument injection in Zabbix 6.0 and later. — ZabbixCWE-77 6.5 -2025-09-12

This page lists every published CVE security advisory associated with Zabbix. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.