Multiple Zabbix Vulnerabilities Patched
ANSSI advisory details multiple Zabbix vulnerabilities allowing denial of service, data confidentiality/integrity breaches, security bypass, and XSS.
CERT-FR has published an advisory covering multiple vulnerabilities discovered in Zabbix, an open-source monitoring solution widely used for IT infrastructure oversight. The flaws affect Zabbix versions 6.x prior to 6.0.48, 7.4.x prior to 7.4.13, and 7.x prior to 7.0.29. Impacts include remote denial of service, breaches of data confidentiality and integrity, security policy bypass, and indirect remote code injection via cross-site scripting (XSS).
Eleven CVEs are referenced in this advisory, corresponding to eleven separate Zabbix security bulletins (ZBX-28067 through ZBX-28077) published by the vendor on 18 August 2026. No indication of active exploitation is provided in the advisory; it is a standard vendor-patch notification. Organizations running affected Zabbix versions should apply the vendor-supplied patches referenced in the official Zabbix security bulletins as soon as practicable, particularly given Zabbix's common deployment in monitoring critical infrastructure and enterprise networks.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1039
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free