Zero Day Monitor
DashboardVulnerabilitiesTrendingZero-DaysNews
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
975 articles · 105176 vulns · 36/41 feeds (7d)
← Back to list
—
CVE-2026-23923EXPLOITED
Zabbix · Zabbix

An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The impact depends on environment setup but appears limited at this time.

Description

An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The impact depends on environment setup but appears limited at this time.

Affected Products

VendorProductVersions
ZabbixZabbixZBX-27638, ZBX-27639, ZBX-27640, ZBX-27641, ZBX-27642

References

  • https://support.zabbix.com/browse/ZBX-27641

Related News (2 articles)

Tier B
BSI Advisories1d ago
[NEU] [hoch] Zabbix: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR2d ago
Multiples vulnérabilités dans Zabbix (25 mars 2026)
→ No new info (linked only)
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-470
Published3/24/2026
Last enriched8h agov3
Trending Score46
Source articles2
Independent2
Info Completeness8/14
Missing: cvss, epss, kev, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Version History

v3
Last enriched 8h ago
v3Tier B8h ago

Updated severity to HIGH and marked the vulnerability as actively exploited with an exploit available.

severityexploitAvailableactivelyExploited
via CERT-FR
v2Tier B8h ago

Added vendor and product information for Zabbix, updated severity to HIGH, and marked the vulnerability as actively exploited with available exploits.

vendorproductaffectedVersions
via CERT-FR
v19h ago

Initial creation