CVE-2026-59788
- EPSS 0.25%
- Veröffentlicht 05.10.2026 10:29:43
- Zuletzt bearbeitet 06.10.2026 15:27:05
The email media type OAuth form passes the Authorization endpoint value to window.open() without validating the URL scheme, so a javascript: URL is executed in the browser. This means a crafted media type configuration, deliverable as an import file,...
CVE-2026-59787
- EPSS 0.23%
- Veröffentlicht 05.10.2026 10:29:20
- Zuletzt bearbeitet 06.10.2026 15:27:05
The Perl SNMP trap receiver script shipped with Zabbix does not properly neutralize the ZBXTRAP record delimiter in trap content. This means someone able to send SNMP traps can inject a record targeting another host, resulting in a loss of integrity.
CVE-2026-59786
- EPSS 0.2%
- Veröffentlicht 05.10.2026 10:29:01
- Zuletzt bearbeitet 06.10.2026 15:27:05
Zabbix Server and Proxy accept the active agent heartbeat message regardless of the configured PSK or certificate authentication. This means someone with access to the Zabbix trapper port can report an arbitrary host using an active agent as availabl...
CVE-2026-59785
- EPSS 0.16%
- Veröffentlicht 05.10.2026 10:28:30
- Zuletzt bearbeitet 06.10.2026 15:27:05
Host search in Frontend allows filtering by fields that are not displayed, including stored IPMI and PSK credentials. A user with read access can guess a credential and see from the search result whether the guess was right, letting them uncover it.
CVE-2026-59783
- EPSS 0.23%
- Veröffentlicht 05.10.2026 10:28:09
- Zuletzt bearbeitet 06.10.2026 15:27:05
The Zabbix Server/Proxy has a vulnerability where binary items can crash the Server/Proxy on certain NULL byte input leading to potential loss of availability. This only affects deployments where MySQL/MariaDB database is used as the Zabbix database.
CVE-2026-59782
- EPSS 0.24%
- Veröffentlicht 05.10.2026 10:27:34
- Zuletzt bearbeitet 06.10.2026 15:27:05
The JavaScript preprocessing (Duktape) engine on Zabbix server has a vulnerability where a limited administrator is able to read raw heap data potentially resulting in leaked data from other running preprocessors not available to said administrator.
CVE-2026-59781
- EPSS 0.11%
- Veröffentlicht 18.08.2026 12:21:29
- Zuletzt bearbeitet 23.09.2026 15:42:02
When Zabbix Agent was installed on Windows into a custom installation directory, the installer did not verify whether the selected directory had secure access permissions. If the target directory allowed unauthorized users to modify its contents, an ...
CVE-2026-23938
- EPSS 0.3%
- Veröffentlicht 18.08.2026 12:20:52
- Zuletzt bearbeitet 23.09.2026 15:41:10
An authenticated administrator is able to crash Zabbix server or proxy by creating specifically crafted preprocessing/script item JavaScript scripts, leading to potential denial of service.
CVE-2026-23937
- EPSS 0.28%
- Veröffentlicht 18.08.2026 12:20:16
- Zuletzt bearbeitet 23.09.2026 14:06:41
The Zabbix API host.get action can be exploited by authenticated users to extract a host's PSK key leading to potential loss of data integrity.
CVE-2026-23935
- EPSS 0.17%
- Veröffentlicht 18.08.2026 12:19:38
- Zuletzt bearbeitet 23.09.2026 14:17:37
A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item/preprocessing (JavaScript) HttpRequest logic, leading to potential confidentiality loss.