CVE-2026-23934: Zabbix
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
An authenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend validate.api.exists action, leading to potential denial of service.
Affected products
- Zabbix Zabbix: from 7.4.0, before 7.4.12 (fixed in 7.4.12)
Published 2026-08-18. Last modified 2026-09-23.