# Multiple Zabbix Vulnerabilities Patched

Published: 2026-08-18 · Severity: routine
Canonical: https://vorant.io/reports/d91e31d7-0591-5f35-9c5b-e2e41a51e673/multiple-zabbix-vulnerabilities-patched

> ANSSI advisory details multiple Zabbix vulnerabilities allowing denial of service, data confidentiality/integrity breaches, security bypass, and XSS.

CERT-FR has published an advisory covering multiple vulnerabilities discovered in Zabbix, an open-source monitoring solution widely used for IT infrastructure oversight. The flaws affect Zabbix versions 6.x prior to 6.0.48, 7.4.x prior to 7.4.13, and 7.x prior to 7.0.29. Impacts include remote denial of service, breaches of data confidentiality and integrity, security policy bypass, and indirect remote code injection via cross-site scripting (XSS).

Eleven CVEs are referenced in this advisory, corresponding to eleven separate Zabbix security bulletins (ZBX-28067 through ZBX-28077) published by the vendor on 18 August 2026. No indication of active exploitation is provided in the advisory; it is a standard vendor-patch notification. Organizations running affected Zabbix versions should apply the vendor-supplied patches referenced in the official Zabbix security bulletins as soon as practicable, particularly given Zabbix's common deployment in monitoring critical infrastructure and enterprise networks.

## Mentioned in this report

- Vulnerabilities: CVE-2026-1199, CVE-2026-23922, CVE-2026-23929, CVE-2026-23930, CVE-2026-23931, CVE-2026-23933, CVE-2026-23934, CVE-2026-23935, CVE-2026-23937, CVE-2026-23938, CVE-2026-59781

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1039

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/d91e31d7-0591-5f35-9c5b-e2e41a51e673/multiple-zabbix-vulnerabilities-patched.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
