CVE-2026-59786

Summary

Zabbix Server and Proxy accept the active agent heartbeat message regardless of the configured PSK or certificate authentication. This means someone with access to the Zabbix trapper port can report an arbitrary host using an active agent as available, resulting in a loss of integrity.

Affected Software

VendorProductVersion RangeStatus
ZabbixZabbix7.0.0 <= 7.0.28affected
ZabbixZabbix7.4.0 <= 7.4.12affected

Weaknesses

  • CWE-940: CWE-940: Improper Verification of Source of a Communication Channel

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References