CVE-2026-23930: Zabbix

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

An unauthenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend popup.testtriggerexpr action, leading to potential denial of service.

Affected products

  • Zabbix Zabbix: from 6.0.0, before 6.0.47 (fixed in 6.0.47); from 7.0.0, before 7.0.27 (fixed in 7.0.27); from 7.4.0, before 7.4.11 (fixed in 7.4.11)

Published 2026-08-18. Last modified 2026-09-08.