CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

NCSC-2026-0320 [1.00] [M/H] Kwetsbaarheden verholpen in Zabbix

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6036

As cited

Copy frozen at (site build).

NCSC-2026-0320 [1.00] [M/H] Kwetsbaarheden verholpen in Zabbix

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

NCSC-2026-0320 [1.00] [M/H] Kwetsbaarheden verholpen in Zabbix

Zabbix SIA released patches for multiple vulnerabilities across its monitoring platform, affecting the application programming interface (API), frontend, script items, preprocessing components, and Windows Agent installer. Issues range from authentication bypass via login lockout miscounting to denial of service (DoS) flaws in unauthenticated endpoints, privilege escalation allowing plaintext macro disclosure, and session forgery in Zabbix 7.4 when using SAML authentication. Additional flaws enable memory disclosure in JavaScript contexts, host pre-shared key extraction, and unsafe DLL sideloading in Windows installations.

Why it matters: Zabbix administrators and organizations deploying Zabbix must patch immediately; the login lockout bypass, unauthenticated DoS, and session forgery vulnerabilities expose all instances to account compromise and availability loss.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

NCSC-2026-0320 [1.00] [M/H] Kwetsbaarheden verholpen in Zabbix

Zabbix SIA released patches for multiple vulnerabilities across its monitoring platform, affecting the application programming interface (API), frontend, script items, preprocessing components, and Windows Agent installer. Issues range from authentication bypass via login lockout miscounting to denial of service (DoS) flaws in unauthenticated endpoints, privilege escalation allowing plaintext macro disclosure, and session forgery in Zabbix 7.4 when using SAML authentication. Additional flaws enable memory disclosure in JavaScript contexts, host pre-shared key extraction, and unsafe DLL sideloading in Windows installations.

Why it matters: Zabbix administrators and organizations deploying Zabbix must patch immediately; the login lockout bypass, unauthenticated DoS, and session forgery vulnerabilities expose all instances to account compromise and availability loss.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary