Zimbra Zero-Day Lets Hackers Hijack Mail Servers Unauthenticated
Today's cybersecurity digest — CVEs, headline news, quantum computing, and something weird. August 24, 2026
cybr.cx — Daily Digest | August 24, 2026
Critical Vulnerabilities
⚠️ Actively exploited — CVE-2026-73570 | Zimbra Collaboration Suite | CVSS: N/A
An OS command injection flaw in Zimbra ZCS allows unauthenticated attackers to execute arbitrary OS commands as the Zimbra user by sending specially crafted SMTP requests. No authentication required — just network access to the mail server. CISA added this to KEV on August 21 with a patch-due date of today. If you're running ZCS and haven't patched, assume exposure. Isolate SMTP intake and audit Zimbra process activity immediately.
⚠️ Actively exploited — CVE-2026-72529 & CVE-2026-72530 | TrueConf Server | CVSS: N/A
Two chained vulnerabilities in TrueConf Server, both exploited in the wild via port 4307/TCP. CVE-2026-72529 is a missing authentication flaw allowing unauthenticated remote attackers to execute arbitrary scripts; CVE-2026-72530 is a code injection flaw enabling sandbox escape and full host-system code execution. The combination is essentially unauthenticated RCE on any internet-exposed TrueConf deployment. Block port 4307 at the perimeter if patching is not yet possible.
⚠️ Actively exploited — CVE-2026-59310 | VMware vCenter | CVSS: N/A
A path traversal vulnerability in Broadcom's VMware vCenter allows network-adjacent attackers to execute arbitrary code without authentication. vCenter exploitation is perennially high-value for ransomware operators and state actors — a compromised vCenter instance typically means full control of virtualised infrastructure. Patch deadline was August 21; if you missed it, treat this as a fire drill.
⚠️ Actively exploited — CVE-2026-55040 | Microsoft SharePoint | CVSS: N/A
A weak authentication vulnerability in SharePoint allows unauthorised network attackers to bypass security controls. SharePoint remains a prolific target given its role as a document repository and intranet backbone in enterprise environments. Patch due date was August 21 — verify your SharePoint patching cadence and review access logs for anomalous authentication patterns.
⚠️ Actively exploited — CVE-2026-65400 | Apple macOS | CVSS: N/A
An improper authentication bug in macOS Screen Sharing allows a network attacker to authenticate without valid credentials, effectively gaining remote desktop access to unpatched Macs. The patch due date was August 21. Mac fleets in enterprise environments — especially those with Screen Sharing enabled for IT support — should treat this as urgent. Disable Screen Sharing on unpatched systems where operationally feasible.
⚠️ Actively exploited — CVE-2026-33824 | Microsoft IKE Service Extensions | CVSS: N/A
A double-free vulnerability in Microsoft's IKE Service Extensions can be leveraged for remote code execution. IKE sits at the heart of IPsec VPN negotiation, meaning exploitation could affect VPN gateways and infrastructure handling encrypted tunnels. Patch due date was August 21; audit exposure now.
⚠️ Actively exploited — CVE-2026-64849 | MLflow | CVSS: N/A
An SSRF vulnerability in MLflow allows attackers to reach internal services and cloud metadata endpoints, returning response status and body content. In cloud-hosted ML environments this commonly leads to credential theft via IMDS endpoints. MLflow's prevalence in data science and AI/ML pipelines makes this particularly dangerous given how rarely those systems receive the same patch scrutiny as production services.
⚠️ Actively exploited — CVE-2025-62593 | Ray (Ray-Project) | CVSS: N/A
A code injection flaw in the Ray distributed computing framework enables remote code execution, including via Firefox and Safari. Developers using Ray locally may be exposed through browser-based attack surfaces — an unusual and underappreciated vector for ML infrastructure compromise.
CVE-2026-0551 | WordPress PPWP Plugin | CVSS: 8.8 (HIGH)
PHP Object Injection via deserialization in the Password Protect Pages plugin, exploitable by any authenticated Contributor-level user. While no POP chain is confirmed in the plugin itself, co-installed plugins can provide one. Sites using this plugin in multi-author or open-registration configurations should update to 1.9.19+ immediately.
CVE-2026-16149 | WordPress Security Hardener Plugin | CVSS: 8.8 (HIGH)
The Security Hardener plugin — ironically designed to block user enumeration — overwrites permission callbacks on the /wp/v2/users REST endpoint in a way that removes authorisation checks entirely, re-exposing user data to unauthenticated requests. Update to 2.4.5+ and audit REST API exposure.
CVE-2026-78122 | docker-socket-proxy | CVSS: 7.4 (HIGH)
When the CONTAINERS environment variable is set, docker-socket-proxy incorrectly gates read endpoints, allowing attackers to pull container logs, export entire container filesystems, and read arbitrary files via GET requests. If you're using docker-socket-proxy to limit Docker API exposure, verify your CONTAINERS variable configuration and review container data sensitivity.
CVE-2026-78063 | Tenda CH22 Router | CVSS: 7.4 (HIGH)
Remote command injection in the formeditFileName function of Tenda CH22 firmware 1.0.0.1 via the editNameMit argument. A public exploit exists. Tenda consumer routers have a poor patching track record — if network segmentation isn't already isolating these devices, now is the time.
Headline News
Russian backdoor discovered in Slovak traffic speed cameras
Slovak authorities have uncovered a Russian-origin backdoor embedded in traffic speed camera systems deployed across the country's road network. The implant appears designed for persistent covert access rather than immediate disruption, raising questions about how long it had been present and what data may have been exfiltrated or tampered with. The discovery is a sharp reminder that critical national infrastructure extends well beyond power grids and water treatment — transportation monitoring systems collect location data on vehicles and individuals at scale, and their integrity matters for both safety and intelligence purposes. For security practitioners responsible for OT and physical infrastructure, the incident reinforces the need to apply network monitoring and firmware integrity verification to systems that are often treated as set-and-forget hardware. Supply chain provenance for any foreign-manufactured infrastructure component with network connectivity deserves renewed scrutiny.
Iranian threat actors knock UK power plant offline for four days
A cyberattack attributed to Iranian state-aligned threat actors successfully disrupted operations at a UK power generation facility, forcing a four-day shutdown. While full technical details remain limited pending investigation, the incident represents one of the more consequential confirmed OT intrusions against UK energy infrastructure in recent memory. The duration of the outage suggests the attackers achieved meaningful depth — either within industrial control systems or adjacent safety/operational networks — rather than simply hitting IT systems. For energy sector defenders, this underscores the importance of OT network segmentation, out-of-band monitoring, and tested manual fallback procedures; the ability to operate through a cyber-induced disruption, not just prevent one, is increasingly a baseline expectation.
Android malware found pre-installed in automotive head unit firmware
Researchers have identified malware embedded within the firmware of Android-based automotive head units — the infotainment systems now standard in a wide range of vehicles. The malware was present at the firmware level, meaning it survives factory resets and is invisible to users who assume an untampered device. Beyond the privacy implications of a compromised in-car system with access to location data, contacts, and Bluetooth-paired devices, the finding highlights a supply chain integrity problem in the automotive industry, where aftermarket and OEM head units often source firmware from opaque third-party vendors. Security teams working in fleet management, automotive OEM supply chains, or mobility services should treat head unit firmware with the same scepticism now applied to other embedded systems.
Schrödinger's Feed
Researchers at Brookhaven National Laboratory and Stony Brook University have demonstrated the first US free-space quantum network link spanning 13 miles, using free-space optical (FSO) transmission rather than fibre. Free-space quantum links are significant because they can extend quantum networks across distances and terrains where laying quantum-capable fibre is impractical, potentially forming a backbone for future quantum-secured communication infrastructure. Unlike classical encrypted links, a quantum network transmitting entangled states can — in principle — detect any interception attempt, since measurement disturbs the quantum state. Practitioners planning long-horizon cryptographic infrastructure should note that physical quantum networking is advancing faster than most enterprise roadmaps assume.
/dev/random
The most quietly influential cybersecurity paper circulating in practitioner communities today was published in 1998. Richard Cook's How Complex Systems Fail — a 18-point treatise originally written about medical systems — is doing the rounds again, and it holds up with uncomfortable precision. Its core argument: complex systems are always operating in a degraded state, safety is produced by people actively compensating for known flaws, and catastrophic failure requires multiple simultaneous defect alignments rather than a single root cause. For anyone who has ever filed an incident report blaming "human error," page one is a corrective.