CVE-2026-59786: fallo de gravedad media en Zabbix
Active agent heartbeat missing TLS check
Publicada el
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 6.9epss 0.2%
probabilidad de explotación
0.2%top 91% de las CVE
explotación observada
noninguna fuente lo reporta
Zabbix Server and Proxy accept the active agent heartbeat message regardless of the configured PSK or certificate authentication. This means someone with access to the Zabbix trapper port can report an arbitrary host using an active agent as available, resulting in a loss of integrity.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Productos afectados
Zabbix · ZabbixCVEs relacionadas — Zabbix
En el mismo producto, de las más peligrosas a las menos.
CVE-2024-42327CRITICALSQL injection in user.get APIEPSS 78.7%CVE-2024-22120CRITICALTime Based SQL Injection in Zabbix Server Audit LogEPSS 76.6%CVE-2013-3628—CVE-2013-3628EPSS 67.5%CVE-2023-29452MEDIUMRemove possibility to add html into Geomap attribution fieldEPSS 64.1%CVE-2024-36465HIGHSQL injection in Zabbix APIEPSS 39.9%CVE-2026-23921HIGHBlind, read-only SQL injection in Zabbix API via sortfield parameterEPSS 3.9%
Referencias
https://support.zabbix.com/browse/ZBX-28196