CVE Tools

Zabbix

143 CVEs tracked. 2 of them are in CISA KEV.

This hub aggregates every CVE we track for Zabbix, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.

Zabbix CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Zabbix CVEs per month
MonthCVEs
2024-100
2024-1114
2024-120
2025-010
2025-020
2025-030
2025-045
2025-054
2025-060
2025-070
2025-080
2025-094
2025-104
2025-110
2025-123
2026-010
2026-020
2026-036
2026-040
2026-053
2026-060
2026-070
2026-0811
2026-090

Severity

How the 143 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical2115%
  • High3625%
  • Medium6344%
  • Low2316%

Latest CVEs

The 15 most recently published vulnerabilities affecting Zabbix.

  1. CVE-2026-59781Improper validation of custom installation directories on Windows could allow installation into locations with unsafe permissions, increasing the risk of DLL sideloading.7.8
  2. CVE-2026-23938Server DoS via JavaScript preprocessing or script items4.9
  3. CVE-2026-23937Host PSK extraction in Zabbix API6.5
  4. CVE-2026-23935Use-after-free read in script item/preprocessing HttpRequest body4.9
  5. CVE-2026-23934Frontend DoS via the validate.api.exists action6.5
  6. CVE-2026-23933Hardcoded session key in Zabbix 7.49.1
  7. CVE-2026-23931Frontend plaintext macro value enumeration via the validatate.api.exists action4.3
  8. CVE-2026-23930Frontend DoS via the popup.testtriggerexpr action7.5
  9. CVE-2026-23929Prototype pollution leading to stored XSS5.4
  10. CVE-2026-1199API and Frontend login lockout race condition3.7
  11. CVE-2026-23922Email media OAuth secret leak to Super Admin4.9
  12. CVE-2026-23928Stored XSS vulnerability in the Item history/Plain text widget6.8
  13. CVE-2026-23927Agent 2 Oracle plugin TNS connection string injection via the 'service' parameter6.5
  14. CVE-2026-23926Stored XSS vulnerability in Host navigator widget maintenance tooltip6.8
  15. CVE-2026-23924Agent 2 Docker plugin arbitrary file read via Docker API injection4.9

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store