LIVE · cybersecurity feed
Live wire
CVE-2026-19478 · GitLab Critical GraphQL Flaw Actively ExploitedCVE-2026-73570 · Poland’s CERT Warns of Active Exploitation of Critical Zimbra Collaboration Suite FlawCISA Urges Immediate Patching of Exploited TrueConf VulnerabilitiesCVE-2026-12569 · Cl0p Targets 40+ Organizations Through PTC Windchill FlawCVE-2026-69836 · Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code ExecutionManic: The Android Malware That Exfiltrates Data Even When the Phone Is OfflineHackers poison arrayref Rust crate to push infostealer malwareNSA, CISA, FBI, DOE, and EPA Warn of Active AI-Assisted Attacks on Siemens S7 PLCsSenators press TikTok over withholding of safety features for some usersAI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure
CVE-2026-73570critical

Poland’s CERT Warns of Active Exploitation of Critical Zimbra Collaboration Suite Flaw

CERT Polska confirmed active exploitation of CVE-2026-73570, a critical unauthenticated RCE in Zimbra Collaboration Suite patched on July 20. CERT Polska, Poland’s national computer emergency response team, confirmed this week that threat actors are actively exploiting a critical vulnerability in Zimbra Collaboration Suite tracked as CVE-2026-73570. The flaw allows unauthenticated remote code exec

zeroday.news ·

CERT Polska has confirmed active exploitation of a critical unauthenticated remote code execution vulnerability in Zimbra Collaboration Suite, identified as CVE-2026-73570. The flaw, which allows attackers to execute arbitrary shell commands with the privileges of the `zimbra` user, was patched by Zimbra on July 20, 2026, in version 10.1.20. Active exploitation was confirmed less than a month later, on August 21, 2026.

The vulnerability stems from a sanitization failure within Zimbra's SNMP monitoring component. It specifically affects instances where the optional `zimbra-snmp` package is installed, SNMP trap notifications are enabled via the `snmp_notify` parameter, and the `swatchdog` service is running. While `zimbra-snmp` is an optional package, the `swatchdog` service, which processes SNMP notifications, is enabled by default on most Zimbra installations.

Given the ongoing exploitation campaign, CERT Polska has issued recommendations for administrators to verify their Zimbra logs and file systems for indicators of compromise. They advise checking `/var/log/zimbra.log` for entries indicating a service status change where a malicious payload transitions from "stopped" to "running" and back, which signifies command execution. Additionally, administrators should inspect the directories `/opt/zimbra/jetty/webapps/`, `/opt/zimbra/jetty_base/webapps/`, and `/tmp/` for any files created by the `zimbra` user within the last 30 days, as these could indicate dropped web shells for persistent access.

The exposure to this vulnerability is significant, with over 12,100 Zimbra servers currently reachable from the internet, according to Shadowserver. Europe and Asia each account for approximately 4,400 of these exposed servers. This figure does not differentiate between patched and unpatched instances or between production servers and honeypots, meaning the actual attack surface is likely smaller but still substantial.

Zimbra solutions have historically been targets for sophisticated threat actors. Previous incidents include exploitation by the Russian espionage group Winter Vivern in February 2023, which used a reflected XSS flaw to steal emails from NATO-aligned organizations. In October 2024, US and UK agencies warned of APT29, linked to Russia's Foreign Intelligence Service, targeting vulnerable Zimbra servers to steal credentials. More recently, in March 2026, APT28, associated with Russian military intelligence, exploited a stored XSS vulnerability against Ukrainian government Zimbra deployments.

The current vulnerability, CVE-2026-73570, presents a particularly high risk due to its unauthenticated nature, the default activation of the vulnerable service component, and the large number of internet-exposed Zimbra servers. Organizations, especially those in sectors frequently targeted by state-backed groups, are urged to prioritize patching and implement the recommended checks to mitigate the threat.

vulnerabilitypatchnation-state
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

U.S. CISA adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: TrueConf Server is an on-premises video conferencing and unified communications platform developed by TrueCon

vulnerability

Microsoft Rolls Out 22 Fresh Security Patches

Most of the fixes resolve code execution, privilege escalation, and information disclosure vulnerabilities. The post Microsoft Rolls Out 22 Fresh Security Patches appeared first on SecurityWeek.

cisahigh

CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities

CISA has issued a directive for immediate patching of critical vulnerabilities affecting TrueConf software. The Head Mare hacktivist group is actively exploiting these flaws to distribute the PhantomCore malware. Organizations using TrueConf are urged to apply the necessary updates to prevent further compromise.

security

Calling on Cyber Pros to Help Defend City Hall

Government agencies with smaller budgets need support — and here's how you can help.

ai

More Incidents of AIs Going Rogue in Cybersecurity Challenges

The AI Security Institute has a new report of AI systems engaging in “unsanctioned behavior”—what I have been calling “genie behavior—while being tested on their cybersecurity capabilities. The incident stemmed from a single evaluation where agents were given a task of solving a cyber security challenge. We ran this challenge 122 times across several models. Our investigation found that in 10 of t

security

Rust Supply Chain Attack Linked to North Korean Hackers

Hackers pushed a poisoned arrayref version that added a dependency to fetch a malicious payload from a remote server. The post Rust Supply Chain Attack Linked to North Korean Hackers appeared first on SecurityWeek.