Zabbix vulnerabilities
6 CVEs tracked
Our reporting indicates Zabbix, including version 7.4, is affected by several critical vulnerabilities. Key themes include the leakage of Frontend session signing keys into the database seed (CVE-2026-23933), a permissive Windows Agent installer (CVE-2026-59781), and the extraction of PSK keys by authenticated users (CVE-2026-23937). Related issues also involve denial of service (CVE-2026-23938) and out-of-bounds memory reads (CVE-2026-23935). Defenders must urgently update Zabbix to the latest version, review the database seed value especially in environments using SAML and guest users, and audit Windows Agent custom installation directories for insecure permissions.
Azərbaycanca: Hesabatlarımızda Zabbix 7.4 versiyası da daxil olmaqla bir sıra kritik boşluqlarla bağlı görünür. Əsas mövzular cəbhə sessiya açarlarının sızması (CVE-2026-23933), Windows agent quraşdırıcısında icazə yoxlanışının olmaması (CVE-2026-59781) və autentifikasiya olunmuş istifadəçilər tərəfindən PSK açarının ələ keçirilməsi (CVE-2026-23937) ilə bağlıdır. Əlaqəli CVE-lər arasında həmçinin xidmət rəddi (CVE-2026-23938) və yaddaşdan kənar oxuma (CVE-2026-23935) zəiflikləri var. Müdafiəçilər dərhal Zabbix-i ən son versiyaya yeniləməli, xüsusilə SAML və qonaq istifadəçilərin aktiv olduğu mühitlərdə verilənlər bazası seed dəyərini nəzərdən keçirməli, Windows agent quraşdırma qovluqlarının icazələrini yoxlamalıdır.
This vendor's CVEs6
This hub is built from skopnix's own reporting on Zabbix: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.