Zabbix 7.4.14
Zabbix 7.4.14 is available. The vendor release notes list the changes and fixes it contains.
Security intelligence for your infrastructure.
Ubuntu Server, Windows Server, Proxmox VE, Plesk, FortiGate / FortiOS and 6 more platforms
— track vulnerabilities, critical patches and release news on a single screen. Stay a step ahead with verified, prioritised and actionable intelligence.
Zabbix 7.4.14 is available. The vendor release notes list the changes and fixes it contains.
Zabbix 7.0.30 is available. The vendor release notes list the changes and fixes it contains.
Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter processing was not filtering dangerous properties like __proto__, combined with jQuery's unsafe element creation that traversed the prototype chain.
In Zabbix 7.4 the cryptographic key used for signing Frontend sessions has been erroneously written to the database seed. Currently the only known exploitation scenario is for deployments that utilize both - SAML authentication and guest users. In such cases the key can be used to forge valid session cookies, potentially leading to unauthorized access. For other Zabbix deployments this does not have a known impact.
Zabbix 7.4.13 is available. The vendor release notes list the changes and fixes it contains.
Zabbix 7.0.29 is available. The vendor release notes list the changes and fixes it contains.
Zabbix 6.0.48 is available. The vendor release notes list the changes and fixes it contains.
Zabbix 7.4.12 is available. The vendor release notes list the changes and fixes it contains.
Zabbix 6.0.47 is available. The vendor release notes list the changes and fixes it contains.
Zabbix 7.0.28 is available. The vendor release notes list the changes and fixes it contains.
The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized actions depending on which user opens a dashboard containing these widgets. The malicious JavaScript would have to come from a monitored host controlled by the attacker. Note: the Item history widget is a replacement for the Plain text widget since Zabbix 7.0.
An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to perform unauthorized actions depending on which user opens the tooltip.
Google patched a high-severity privilege escalation vulnerability in the Pixel Cellular Modem tracked as CVE-2026-58704. NIST records indicate the iss...
Leaked credentials or published vulnerability notices can be turned into attacks before defenders finish triage; attackers are shortening the time fro...
Acronis reported that CVE-2026-87886 (CVSS 7.8), a local privilege escalation rooted in insecure file permissions in the Acronis Backup plugin for cPa...
Vulnerabilities and release notes for the platforms you follow, in one email every morning. You choose which platforms to track, and you can leave at any time.
Already subscribed? Manage your preferences