CERT-FR issues advisory on Zabbix flaws
Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.
CERT-FR warns of multiple Zabbix vulnerabilities enabling remote DoS, data confidentiality/integrity breaches, XSS, and security bypass; patches available.
CERT-FR has published an advisory covering six vulnerabilities (CVE-2026-59782, 59783, 59785, 59786, 59787, 59788) affecting Zabbix monitoring software, a widely deployed open-source network and infrastructure monitoring platform. The flaws affect Zabbix 6.0.x prior to 6.0.48, 7.0.x prior to 7.0.29, and 7.4.x prior to 7.4.13.
The vulnerabilities collectively allow a remote attacker to cause denial of service, compromise data confidentiality and integrity, bypass security policy controls, and perform indirect remote code injection via cross-site scripting (XSS). No evidence of active exploitation in the wild is mentioned in the advisory. CERT-FR directs administrators to the Zabbix vendor security bulletins (ZBX-28193 through ZBX-28198) for patch details.
Defenders running affected Zabbix versions should prioritize upgrading to 6.0.48, 7.0.29, or 7.4.13 or later as appropriate, and review exposure of Zabbix web interfaces and APIs given the mix of XSS, data exposure, and DoS risks typical of monitoring platform compromises.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1261
What this brief leaves out
This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.
It sits in a corpus of 10,758 reports from 152 sources, 489 of them written in the last seven days, and it grows through the day.
A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.
Create a free account What it costs