# CERT-FR issues advisory on Zabbix flaws

Published: 2026-10-05 · Severity: routine · Sectors: technology, infrastructure
Canonical: https://vorant.io/reports/9571178e-4773-596a-9d6c-ea03cba19d1a/cert-fr-issues-advisory-on-zabbix-flaws

> CERT-FR warns of multiple Zabbix vulnerabilities enabling remote DoS, data confidentiality/integrity breaches, XSS, and security bypass; patches available.

CERT-FR has published an advisory covering six vulnerabilities (CVE-2026-59782, 59783, 59785, 59786, 59787, 59788) affecting Zabbix monitoring software, a widely deployed open-source network and infrastructure monitoring platform. The flaws affect Zabbix 6.0.x prior to 6.0.48, 7.0.x prior to 7.0.29, and 7.4.x prior to 7.4.13.

The vulnerabilities collectively allow a remote attacker to cause denial of service, compromise data confidentiality and integrity, bypass security policy controls, and perform indirect remote code injection via cross-site scripting (XSS). No evidence of active exploitation in the wild is mentioned in the advisory. CERT-FR directs administrators to the Zabbix vendor security bulletins (ZBX-28193 through ZBX-28198) for patch details.

Defenders running affected Zabbix versions should prioritize upgrading to 6.0.48, 7.0.29, or 7.4.13 or later as appropriate, and review exposure of Zabbix web interfaces and APIs given the mix of XSS, data exposure, and DoS risks typical of monitoring platform compromises.

## Mentioned in this report

- Vulnerabilities: CVE-2026-59782, CVE-2026-59783, CVE-2026-59785, CVE-2026-59786, CVE-2026-59787, CVE-2026-59788

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1261

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/9571178e-4773-596a-9d6c-ea03cba19d1a/cert-fr-issues-advisory-on-zabbix-flaws.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
