CVE-2026-23937: Zabbix

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

The Zabbix API host.get action can be exploited by authenticated users to extract a host's PSK key leading to potential loss of data integrity.

Affected products

  • Zabbix Zabbix: from 6.0.0, before 6.0.47 (fixed in 6.0.47); from 7.0.0, before 7.0.28 (fixed in 7.0.28); from 7.4.0, before 7.4.12 (fixed in 7.4.12)

Published 2026-08-18. Last modified 2026-09-23.