View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Attackers Exploit Zimbra Command-Injection Flaw for Unauthenticated

🚨 ACTIVE EXPLOITATION

  • Attackers Exploit Zimbra Command-Injection Flaw for Unauthenticated RCE
    Attackers are actively exploiting a Zimbra Collaboration Suite vulnerability.

    • Zimbra Collaboration Suite users are affected, including government, university, and public-sector organizations.
    • CVE-2026-73570 is an OS command-injection flaw in ZCS before version 10.1.20.
    • The flaw requires the optional zimbra-snmp package and SNMP notifications to be enabled.
    • Unauthenticated attackers send specially crafted SMTP requests to execute operating-system commands as the Zimbra user.
    • Reported indicators include suspicious Zimbra service restarts in /var/log/zimbra.log and recent files in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, or /tmp/.
      πŸ“„ Source: cisa.gov Β· πŸ“Ž Coverage: thehackernews.com Β· πŸ‘ via Cybersecurity Dive
  • DDoS attack disrupts Norway’s government digital services
    A DDoS attack has disrupted Norway’s shared government digital infrastructure.

    • Norwegian public-sector services and residents using government portals are affected.
    • ID-porten, Altinn, MinID, eSignering and other shared services experienced outages or access problems.
    • The attack targeted infrastructure operated by Digdir’s provider Vivicta.
    • Attackers flooded the infrastructure with traffic, with activity continuing in waves for about 30 hours.
    • Digdir reported no evidence of system compromise or personal-data exposure.
      πŸ“„ Source: status.digdir.no Β· πŸ“Ž Coverage: therecord.media Β· πŸ‘ via BleepingComputer

πŸ•΅οΈ RESEARCH & DEEP DIVES

  • Chinese Hackers Scale Cyberattacks With Low-Cost AI Tools
    Chinese-linked hackers are using AI tools to automate and scale cyberattacks.

    • Chinese-speaking operators are targeting government agencies and internet-facing organizations worldwide.
    • Targets include Windows and Linux servers, government web applications, and exposed workflow automation systems.
    • Attackers combine DeepSeek, Hermes Agent, OpenClaw, and up to eight AI subagents for reconnaissance, vulnerability analysis, exploitation, and persistence.
    • The operations use FOFA asset discovery, public exploit code, Telegram command-and-control, web shells, and AI-generated scripts.
    • Observed targets include Langflow 1.3.4, n8n, Zimbra, AjaxPro, Nacos, Telerik UI, Citrix NetScaler, and Marimo systems.
      πŸ“Ž Coverage: darkreading.com Β· πŸ‘ via securityboulevard.com (discovered)
  • Call of Duty 1 Linux server has post-authentication RCE
    Researchers found a post-authentication RCE in Call of Duty 1’s Linux server.

    • The issue affects operators running Call of Duty 1’s Linux dedicated server, cod_lnxded.
    • The rcon map command overflows a 72-byte stack buffer with an attacker-controlled map name.
    • The exploit overwrites the return address, uses a jmp esp gadget, and executes shellcode on the server’s executable stack.
    • The attack requires authenticated rcon access and was demonstrated by spawning a shell in the game-server process.
      πŸ“Ž Coverage: zolder.io Β· πŸ‘ via r/netsec

πŸ“‹ ADVISORIES

πŸ”“ CVEs & KEV

  • CVE-2026-55585 β€” CVSS 8.8 β€” QWED: Authenticated Remote Code Execution via Unsafe SymPy parse_expr()QWED...

  • CVE-2026-75498 β€” CVSS 8.6 β€” Webkul QloApps SQL injectionWebkul QloApps does not validate request paramete...

  • CVE-2026-75497 β€” CVSS 8.6 β€” Webkul QloApps SQL injectionWebkul QloApps does not validate request paramete...

  • CVE-2026-75496 β€” CVSS 8.6 β€” Webkul QloApps improper file upload validationWebkul QloApps does not perform...

  • CVE-2026-55557 β€” CVSS 8.6 β€” browse-mcp: Arbitrary file write via unconfined download and state pathsbrows...

  • CVE-2026-79784 β€” CVSS 8.6 β€” Vocos Arbitrary Class Instantiation Leads to Remote Code Execution (CVE-2026-79784)

  • CVE-2026-64204 β€” CVSS 8.5 β€” Out-of-Bounds Write Vulnerability in NI LabVIEW when loading VIThere is a mem...

  • CVE-2026-64203 β€” CVSS 8.5 β€” Out-of-Bounds Read Vulnerability in NI LabVIEW when loading VIThere is a memo...

  • CVE-2026-64202 β€” CVSS 8.5 β€” Out-of-Bounds Read Vulnerability in NI LabVIEW when loading VIThere is a memo...

  • CVE-2026-64201 β€” CVSS 8.5 β€” Out-of-Bounds Read Vulnerability in NI LabVIEW when loading VIThere is a memo...

  • CVE-2026-16234 β€” CVSS 8.5 β€” Out-of-Bounds Read Vulnerability in NI LabVIEW when loading VIThere is a memo...

  • CVE-2026-16233 β€” CVSS 8.5 β€” Out-of-Bounds Write Vulnerability in NI LabVIEW when loading VIThere is a mem...

  • CVE-2026-55553 β€” CVSS 7.5 β€” urllib: Cross-origin redirects preserve credential-bearing request headers, l...

  • CVE-2026-59189 β€” CVSS 7.1 β€” OpenEXR: Out-of-bounds read in DeepImageChannel::row() for non-zero dataWindo...

  • CVE-2026-59187 β€” CVSS 7.1 β€” OpenEXR: exrmetrics deep pixelmode heap buffer overflowOpenEXR is the referen...

  • CVE-2026-59186 β€” CVSS 7.1 β€” OpenEXR: Heap out-of-bounds write in TiledRgbaInputFile via integer overflow ...

  • CVE-2026-59184 β€” CVSS 7.1 β€” OpenEXR: OpenEXRUtil FlatImageChannel row nonzero dataWindow heap OOB writeOp...

  • CVE-2026-78468 β€” CVSS 6.5 β€” FluentCRM Pro through 3.1.12 - Authenticated (Author+) SQL InjectionThe FluentCRM ...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check