LIVE · cybersecurity feed
Live wire
Australia Warns of Active Exploitation of Critical TeamCity Server FlawCVE-2026-21962 · Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical DataUS sanctions Iranian cyber actors as UK discloses power plant attackHackers target WordPress sites in miniOrange auth bypass attacksFake GTA 6 Extended Look and demo sites deliver an infostealerCVE-2026-63520 · Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)Fake Microsoft security scans trick victims into uninstalling their antivirusCVE-2026-19478 · ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and MoreThe Vulnerability Gap: Why Discovery Is Outrunning RepairCISA’s logging guidance works beyond government
CVE-2026-73570

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks

At least 274 internet-facing Zimbra instances have been compromised by unknown attackers via CVE-2026-73570, the Shadowserver Foundation shared on Monday. About CVE-2026-73570 Zimbra Collaboration Suite (ZCS) is a communication and collaboration platform popular with organizations that need to have control over their data or can’t afford a pricy alternative service like Microsoft 365 or Google Wor

zeroday.news ·

At least 274 internet-facing Zimbra Collaboration Suite (ZCS) instances have been compromised through exploitation of CVE-2026-73570, a code injection vulnerability. The Shadowserver Foundation, a nonprofit security organization, reported the rising number of compromises after initially identifying 155 affected instances on August 20.

CVE-2026-73570 impacts Zimbra mail servers configured with the optional `zimbra-snmp` package and SNMP notifications enabled. The flaw stems from insufficient sanitization of untrusted input during SNMP notification processing. This allows an unauthenticated attacker to send specially crafted SMTP requests, potentially leading to the execution of arbitrary operating system commands under the privileges of the Zimbra user.

Synacor, the vendor behind Zimbra, released a patch for the vulnerability in ZCS version 10.1.20 on July 20, 2026. Prior to the official fix, the vulnerability was publicly disclosed on June 26, 2026, and a temporary mitigation was made available to administrators.

The in-the-wild exploitation of CVE-2026-73570 was first flagged by the Polish CERT, which provided indicators of compromise including specific log entries and created files. The Shadowserver Foundation leveraged this information in its daily internet-wide scans to identify compromised systems.

While at least 8,200 Zimbra instances have yet to update to ZCS v10.1.20, it's important to note that not all of these are necessarily vulnerable. The exploitability of CVE-2026-73570 is contingent on a non-default configuration, specifically the installation of the `zimbra-snmp` package and enabled SNMP notifications.

The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-73570 to its Known Exploited Vulnerabilities catalog. CISA has mandated that US federal civilian agencies address the vulnerability within three days and investigate for any signs of compromise. The identity of the attackers behind these ongoing exploits remains unknown.

vulnerabilitypatch
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerabilitycritical

Australia Warns of Active Exploitation of Critical TeamCity Server Flaw

Australian officials are urging TeamCity customers to patch an actively exploited critical flaw, which follows a similar warning from the US government

vulnerability

CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw

Disclosed in January and honeypots buzzed soon after, CISA says it’s finally time for the USG to plug the gap

malware

First Malware Built Specifically for Car Head Units Fuels Botnet

Kaspersky researchers have linked the malware to the BadBox botnet, which has ensnared millions of devices. The post First Malware Built Specifically for Car Head Units Fuels Botnet appeared first on SecurityWeek.

security

The County Prosecutors Who Became ICE Informants

Illinois prosecutors shared defendants’ personal data with federal immigration agents without criminal warrants, public disclosure, or legislative oversight.

malware

Fake Minecraft Clients Deliver WeedHack Malware Despite Infrastructure Takedown

A threat actor keeps spreading the WeedHack malware to Minecraft players despite its original infrastructure taken down in July

security

ReliaQuest Rejects Compromise Claims After ShinyHunters Incident

ReliaQuest has detailed a social engineering attack linked to ShinyHunters, denying reports that the threat actor successfully compromised its systems