< Back to all clusters
[TECHNOLOGY] · Japan · 3 sources

started · updated

Zabbix agent vulnerability allows potential arbitrary code execution

The Information-technology Promotion Agency (IPA) and JPCERT/CC have announced a DLL loading vulnerability in the Zabbix agent, identified as CVE-2026-59781. The flaw stems from improper file access permission settings during installation.

This vulnerability could allow an attacker to load unauthorized DLLs, potentially leading to the execution of arbitrary code with administrator privileges. Affected versions include all Zabbix agent versions prior to 7.0.24 and all versions prior to 7.4.8. Developers and users are urged to update to the latest versions to mitigate the risk.

Entities

IPA · JPCERT/CC · Zabbix LLC · Zabbix agent