These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-59781 is a medium-severity vulnerability in Zabbix Agent on Windows. The installer did not verify secure access permissions for custom installation directories, allowing an attacker to potentially place a malicious DLL for loading, resulting in DLL sideloading. The installer has been updated to detect unsafe directories and require user confirmation before proceeding with installation in such locations.
An authenticated administrator can crash the Zabbix server or proxy by creating specifically crafted preprocessing/script item JavaScript scripts, potentially leading to a denial of service. This issue affects Zabbix versions 6.0.0 to 6.0.47, 7.0.0 to 7.0.27, and 7.4.0 to 7.4.11. The vulnerability allows an authenticated administrator with access to create preprocessing/script item JavaScript scripts to c [truncated]
The Zabbix API host.get action vulnerability allows authenticated users to extract a host's PSK key, potentially leading to data integrity loss. This CVE record, published on 2026-08-18T13:17:21.973Z, indicates a CVSS score of 6 and a severity of MEDIUM. Administrators and users of Zabbix API should be aware of this vulnerability and take necessary precautions to secure their API access. The vulnerability [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T13:17:21.843Z and has not been modified since then. This vulnerability affects Zabbix installations, specifically through a flaw in script item/preprocessing (JavaScript) HttpRequest logic. The vulnerability could potentially lead to confidentiality loss if exploited. Zabbix administrators and us [truncated]
An authenticated user can cause disproportionate CPU load on the Frontend webserver by sending crafted requests to the Frontend validate.api.exists action, potentially leading to denial of service. This vulnerability affects Zabbix installations and has a CVSS score of 5.1, indicating medium severity. System administrators and security teams should verify if their systems are affected, apply necessary pat [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T13:17:21.303Z and has not been modified since then. This CVE affects Zabbix installations, specifically through the Frontend webserver's popup.testtriggerexpr action, which can be exploited by unauthenticated users to cause disproportionate CPU load, potentially leading to denial of service. Admi [truncated]
A prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter processing was not filtering dangerous properties like __proto__, combined with jQuery's unsafe element creation that traversed the prototype chain. This issue has a CVSS score of 8.5 and is considered HIGH severity. Organizations using Zabbix Maps should verify their inventory and apply ven [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T13:17:20.900Z and has not been modified since then. The Zabbix API and Frontend login lockout mechanism has a flaw where several unsuccessful login requests sent simultaneously are not properly counted towards the block counter, potentially allowing for more password guesses than intended. Admini [truncated]
The Item history widget in Zabbix 7.0+ or the Plain text widget in Zabbix 6.0 can execute injected JavaScript when HTML display is enabled, potentially allowing unauthorized actions depending on which user opens a dashboard containing these widgets. The malicious JavaScript must come from a monitored host controlled by the attacker, and defenders should assess exposure and prioritize patching accordingly. [truncated]
A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead to Agent 2 connecting to an attacker-controlled server and leaking Oracle database credentials if they are saved in a named session. The vulnerability allows an attacker to potentially control the connection, leading to unauthorized access and data breaches. Defenders should assess expos [truncated]
An authenticated, non-super administrator can create a maintenance period with a JavaScript payload that is executed by any user opening the tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to perform unauthorized actions depending on which user opens the tooltip. The vulnerability affects Zabbix systems, particularly those with multiple users and critical infr [truncated]
The Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding them to the Docker daemon. This allows an attacker capable of invoking Agent 2 to read arbitrary files from running Docker containers by injecting them via the Docker archive API. The issue arises from insufficient input validation, enabling attackers to exploit this vulnerability. Defenders [truncated]
An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes in Zabbix, potentially leading to code execution. The impact depends on environment setup, especially for versions 7.4.0 through 7.4.7, and appears limited at this time. Defenders should verify exposure, assess potential impacts, and monitor for vendor patches. This vulnerability allows for [truncated]
A low-privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter. Although query results are not returned directly, an attacker can exfiltrate arbitrary database data through time-based techniques, potentially leading to session identifier disclosure and administrator account compromise.
Authenticated users can inject shell commands due to a regex validation bypass in Zabbix installations. The vulnerability allows for command injection via newline characters when using ^ and $ anchors in user input validation. System administrators and security teams should verify and restrict user input validation, implement proper regex patterns, and monitor for suspicious activity related to shell comm [truncated]
A CVE debrief for CVE-2026-23919 based on the supplied source corpus. The Zabbix Server/Proxy reuses JavaScript contexts for performance reasons, leading to confidentiality loss if a regular Zabbix administrator leaks data for hosts they do not have access to. This vulnerability allows potential data leaks due to the reuse of JavaScript contexts. Defenders should assess exposure and prioritize verificatio [truncated]
CVE-2026-23925 is a medium-severity vulnerability in Zabbix that allows an authenticated user with template/host write permissions to create unauthorized hosts, potentially leading to confidentiality loss. The vulnerability has a CVSS score of 5.1 and was published on March 6, 2026.
CVE-2022-23134 is a Zabbix Frontend improper access control vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2022-02-22. Because it is on the KEV list, organizations should treat it as a high-priority remediation item and follow vendor update guidance without delay. The supplied sources do not include affected versions or exploit details, so the safest response is to identif [truncated]
CVE-2022-23131 is a Zabbix Frontend authentication bypass vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2022-02-22. Because it is on the KEV list, defenders should treat it as an active risk and prioritize vendor-guided remediation promptly.
CVE-2016-10134 is a critical SQL injection vulnerability in Zabbix. According to NVD, the flaw affects Zabbix before 2.2.14 and 3.0 before 3.0.4, and can let a remote attacker execute arbitrary SQL commands through the toggle_ids array parameter in latest.php. The CVSS vector is network-based, requires no privileges or user interaction, and is rated 9.8 (Critical).
CVE-2016-4338 is a high-severity injection flaw in Zabbix agent's mysql user parameter configuration script. In affected deployments, using userparameter_mysql.conf with a shell other than bash can allow abuse of the mysql.size parameter to execute arbitrary code or SQL commands. The issue is rated 8.1 HIGH in the supplied NVD record, so Zabbix installations that use this script should be prioritized for [truncated]