Zabbix
6 known vulnerabilities in Zabbix, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-59788 CVSS 5.7 medium The email media type OAuth form passes the Authorization endpoint value to window.open() without validating the URL scheme, so a…
- CVE-2026-59787 CVSS 5.3 medium The Perl SNMP trap receiver script shipped with Zabbix does not properly neutralize the ZBXTRAP record delimiter in trap content. This…
- CVE-2026-59786 CVSS 6.9 medium Zabbix Server and Proxy accept the active agent heartbeat message regardless of the configured PSK or certificate authentication. This…
- CVE-2026-59785 CVSS 5.1 medium Host search in Frontend allows filtering by fields that are not displayed, including stored IPMI and PSK credentials. A user with read…
- CVE-2026-59783 CVSS 2.3 low The Zabbix Server/Proxy has a vulnerability where binary items can crash the Server/Proxy on certain NULL byte input leading to potential…
- CVE-2026-59782 CVSS 6.9 medium The JavaScript preprocessing (Duktape) engine on Zabbix server has a vulnerability where a limited administrator is able to read raw heap…