CVE-2026-23923: Zabbix
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The impact depends on environment setup but appears limited at this time.
Affected products
- Zabbix Zabbix: from 7.4.0, before 7.4.7 (fixed in 7.4.7)
Published 2026-03-24. Last modified 2026-09-10.