CISA has issued a three-day deadline for agencies to patch a Zimbra security vulnerability, CVE-2026-73570, which allows full takeover of a user's communications.

A recently exploited vulnerability in Zimbra, identified as CVE-2026-73570, has prompted a directive from the Cybersecurity and Infrastructure Security Agency (CISA) for federal agencies to apply patches within a three-day window. The flaw is reported to enable a complete takeover of a user's communications, underscoring the critical nature of the exploit and the urgency of mitigation.
The vulnerability, CVE-2026-73570, is described as allowing an attacker to gain full control over a user's communication channels within the Zimbra environment. While the specific technical mechanism of the exploit was not detailed, such takeovers typically involve bypassing authentication, exploiting session management flaws, or leveraging cross-site scripting (XSS) or server-side request forgery (SSRF) vulnerabilities to gain unauthorized access to user sessions or data. The impact of such a compromise can be severe, potentially leading to data exfiltration, impersonation, and further lateral movement within an organization's network.
Zimbra Collaboration Suite is a widely used open-source email and collaboration platform, offering email, calendar, contacts, and other features. Its broad adoption, particularly in enterprise and government sectors, means that vulnerabilities can have a significant reach. Products in this category are frequently targeted due to the sensitive nature of the data they handle and their role as a central communication hub.
The CISA directive, mandating a three-day patching deadline for federal agencies, highlights the active exploitation of this flaw. This rapid turnaround requirement is typically reserved for vulnerabilities that are either actively being exploited in the wild, have a high severity score, or both. For organizations beyond federal agencies, the reported exploitation serves as a strong recommendation to prioritize patching efforts immediately.
General mitigation guidance for this class of issue often includes applying vendor-supplied patches promptly, implementing robust network segmentation, employing multi-factor authentication (MFA), and regularly auditing access logs for suspicious activity. Additionally, organizations are advised to ensure their intrusion detection and prevention systems (IDPS) are up-to-date and configured to detect known exploit patterns.
The incident with CVE-2026-73570 in Zimbra underscores a broader trend in cybersecurity where the window between a vulnerability's discovery and its active exploitation is rapidly shrinking. This necessitates a proactive and agile approach to patch management and incident response across all sectors. Organizations must maintain current inventories of their software assets, subscribe to vendor security advisories, and establish efficient processes for deploying critical security updates to minimize their exposure to emerging threats.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.