[NEW] [high] Zabbix: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in Zabbix to disclose or manipulate information, bypass security mechanisms, conduct a denial of service attack, conduct a cross-site scripting attack and potentially execute code.
CSIRTS triage
- What
- Multiple vulnerabilities in Zabbix allow information disclosure, data manipulation, security bypass, denial of service, cross-site scripting, and potential code execution.
- Who is affected
- Zabbix deployments running vulnerable versions.
- Urgency
- High severity; diverse attack vectors including potential remote code execution and complete information disclosure.
- Action
- Apply Zabbix security patches addressing the eight listed CVEs immediately.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Zabbix
Get an email when a new Zabbix advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2916
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-11990.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-239220.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-239290.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-239300.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-239310.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-239330.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-239340.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-239350.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-239370.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-239380.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-1199 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-23922 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-23929 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-23930 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-23931 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-23933 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-23934 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-23935 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-23937 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-23938 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-59781 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownNCSC-2026-0320 [1.00] [M/H] Vulnerabilities resolved in Zabbixncsc-nl
- unknownCVE-2026-59781: When Zabbix Agent was installed on Windows into a custom installation directory, the installer…nvd
- unknownCVE-2026-23938: An authenticated administrator is able to crash Zabbix server or proxy by creating specificall…nvd
- unknownCVE-2026-23937: The Zabbix API host.get action can be exploited by authenticated users to extract a host's PSK…nvd
- unknownCVE-2026-23935: A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item…nvd
- unknownCVE-2026-23934: An authenticated user is able to cause disproportionate CPU load on the Frontend webserver by …nvd
- unknownCVE-2026-23933: In Zabbix 7.4 the cryptographic key used for signing Frontend sessions has been erroneously wr…nvd
- unknownCVE-2026-23931: The frontend validatate.api.exists action can be exploited by authenticated users to extract p…nvd
- unknownCVE-2026-23930: An unauthenticated user is able to cause disproportionate CPU load on the Frontend webserver b…nvd
- unknownCVE-2026-23929: Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in …nvd
- unknownCVE-2026-23922: The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can…nvd
- unknownCVE-2026-1199: Zabbix API and Frontend login lockout mechanism has a flaw where several unsuccessful login req…nvd
Recent advisories for Zabbix
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownNCSC-2026-0320 [1.00] [M/H] Vulnerabilities resolved in Zabbixncsc-nl · 2026-08-20
- unknownCVE-2026-59781: When Zabbix Agent was installed on Windows into a custom installation directory, the installer…nvd · 2026-08-18
- unknownCVE-2026-23938: An authenticated administrator is able to crash Zabbix server or proxy by creating specificall…nvd · 2026-08-18
- unknownCVE-2026-23937: The Zabbix API host.get action can be exploited by authenticated users to extract a host's PSK…nvd · 2026-08-18
- unknownCVE-2026-23935: A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item…nvd · 2026-08-18
- unknownCVE-2026-23933: In Zabbix 7.4 the cryptographic key used for signing Frontend sessions has been erroneously wr…nvd · 2026-08-18
More from CERT-Bund (BSI) Security Advisories
- high[NEW] [high] Linux Kernel: Multiple vulnerabilities2026-08-25
- medium[NEW] [medium] libTIFF: Multiple Vulnerabilities2026-08-25
- high[NEW] [high] Contao: Multiple Vulnerabilities2026-08-25
- medium[NEW] [medium] Django: Multiple Vulnerabilities2026-08-25
- high[NEW] [high] Red Hat Enterprise Linux (Apicurio Registry): Multiple Vulnerabilities2026-08-25