Zabbix vendor intelligence

Zabbix Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting Zabbix products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Browse Zabbix KEVs Full KEV feed
Total KEVs
2
Known exploited vulnerabilities affecting Zabbix products
In CISA KEV
2
Records also listed in the official catalog
Beyond CISA KEV
0
Additional exploited CVEs absent from CISA KEV
Sensor Observed
0
Zabbix KEVs with sensor-observed exploitation activity

The catalog gap matters for Zabbix exposure

All two exploited Zabbix CVEs tracked here are also listed in CISA KEV. Use product ownership and sensor evidence to prioritize within this portfolio.

100%
Covered by CISA
0%
Beyond CISA
1
Product families

Attested Zabbix CVEs

Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2022-23134

Possible view of the setup pages by unauthenticated users if config file already exists

Frontend Confirmed In CISA 22 Feb 2022
CVE-2022-23131

Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML

Frontend Confirmed In CISA 22 Feb 2022

Showing 2 of 2 Zabbix known exploited vulnerabilities.

Recurring weakness patterns

Access control and authentication bypass by spoofing account for two mapped occurrences across this Zabbix KEV portfolio.

Browse all KEVs →

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.