Changeflow GovPing Data Privacy & Cybersecurity Multiple Zabbix Vulnerabilities Disclosed
Priority review Notice Added Final

Multiple Zabbix Vulnerabilities Disclosed

Favicon for www.cert.ssi.gouv.fr CERT-FR Security Advisories
Published March 25th, 2026
Detected March 25th, 2026
Email

Summary

CERT-FR has issued an advisory regarding multiple vulnerabilities discovered in Zabbix software. These vulnerabilities could allow remote code execution, data breaches, and SQL injection. Affected versions include specific releases of Zabbix 6.0, 7.0, 7.2, and 7.4.

What changed

CERT-FR, the French national cybersecurity agency, has published an advisory detailing multiple critical vulnerabilities found in Zabbix monitoring software. The vulnerabilities, identified by CVE numbers such as CVE-2026-23919 through CVE-2026-23924, can lead to remote code execution, data confidentiality breaches, and SQL injection attacks. The advisory specifically lists affected versions of Zabbix, including 6.0.x prior to 6.0.44, 7.0.x prior to 7.0.23, 7.2.x prior to 7.2.15, and 7.4.x prior to 7.4.7.

Organizations utilizing the affected Zabbix versions are strongly advised to consult the Zabbix security bulletins and apply the necessary patches immediately to mitigate the risks of exploitation. Failure to do so could result in significant data breaches, system compromise, and unauthorized access. The advisory directs users to the vendor's security bulletins for specific patch information and remediation steps.

What to do next

  1. Review Zabbix security bulletins (ZBX-27638 to ZBX-27642) for specific patch details.
  2. Apply available patches to Zabbix versions 6.0.x, 7.0.x, 7.2.x, and 7.4.x to address identified vulnerabilities.
  3. Assess systems for any signs of compromise related to these vulnerabilities.

Source document (simplified)

Premier Ministre S.G.D.S.N

Agence nationale
de la sécurité des
systèmes d'information

Paris, le 25 mars 2026 N° CERTFR-2026-AVI-0353 Affaire suivie par: CERT-FR

Avis du CERT-FR

Objet: Multiples vulnérabilités dans Zabbix

Gestion du document

| Référence | CERTFR-2026-AVI-0353 |
| Titre | Multiples vulnérabilités dans Zabbix |
| Date de la première version | 25 mars 2026 |
| Date de la dernière version | 25 mars 2026 |
| Source(s) | Bulletin de sécurité Zabbix ZBX-27638 du 24 mars 2026
Bulletin de sécurité Zabbix ZBX-27639 du 24 mars 2026
Bulletin de sécurité Zabbix ZBX-27640 du 24 mars 2026
Bulletin de sécurité Zabbix ZBX-27641 du 24 mars 2026
Bulletin de sécurité Zabbix ZBX-27642 du 24 mars 2026 |
Une gestion de version détaillée se trouve à la fin de ce document.


Risques

  • Atteinte à la confidentialité des données
  • Contournement de la politique de sécurité
  • Exécution de code arbitraire à distance
  • Injection SQL (SQLi)

Systèmes affectés

  • Zabbix versions 6.0.x antérieures à 6.0.44
  • Zabbix versions 7.0.x antérieures à 7.0.23
  • Zabbix versions 7.2.x antérieures à 7.2.15
  • Zabbix versions 7.4.x antérieures à 7.4.7

Résumé

De multiples vulnérabilités ont été découvertes dans Zabbix. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une atteinte à la confidentialité des données et une injection SQL (SQLi).

Solutions

Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

Documentation


Gestion détaillée du document

  1. le 25 mars 2026 Version initiale

Named provisions

Risks Affected Systems Summary Solutions Documentation

Source

Analysis generated by AI. Source diff and links are from the original.

Classification

Agency
CERT-FR
Published
March 25th, 2026
Instrument
Notice
Legal weight
Non-binding
Stage
Final
Change scope
Substantive
Document ID
CERTFR-2026-AVI-0353

Who this affects

Applies to
Technology companies
Industry sector
5112 Software & Technology
Activity scope
Vulnerability Management System Monitoring
Geographic scope
France FR

Taxonomy

Primary area
Cybersecurity
Operational domain
IT Security
Compliance frameworks
NIST CSF
Topics
Vulnerability Management Information Security

Get Data Privacy & Cybersecurity alerts

Weekly digest. AI-summarized, no noise.

Free. Unsubscribe anytime.

Get alerts for this source

We'll email you when CERT-FR Security Advisories publishes new changes.

Free. Unsubscribe anytime.