CVE-2026-23935: Zabbix
Medium severity, CVSS 4.9. EPSS: 0.3% chance of exploitation in the next 30 days.
A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item/preprocessing (JavaScript) HttpRequest logic, leading to potential confidentiality loss.
Affected products
- Zabbix Zabbix: from 7.0.0, before 7.0.28 (fixed in 7.0.28); from 7.4.0, before 7.4.12 (fixed in 7.4.12)
Published 2026-08-18. Last modified 2026-09-23.