What you need to know today.
Zimbra RCE Flaw Actively Exploited; Microsoft Patches Critical Entra ID Vulnerability

A remote code execution vulnerability in Zimbra Collaboration (ZCS) before 10.1.20, specifically CVE-2026-73570, has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. This flaw affects the optional zimbra-snmp package when SNMP notifications are enabled, allowing unauthenticated attackers to execute arbitrary code. The vulnerability is due to improper sanitization of untrusted input. Multiple news outlets, including The Hacker News and Cyber Security News, report that this zero-day is under active exploitation. Organizations are urged to patch immediately to mitigate risks.
Microsoft has released patches for a significant number of vulnerabilities, including several critical flaws in Azure and Microsoft Entra ID. Notably, CVE-2026-69836, a deserialization vulnerability in Microsoft Entra ID, is being actively exploited in the wild, as reported by Help Net Security and Cyber Security News. This flaw allows unauthenticated attackers to execute code over a network. Other critical Microsoft vulnerabilities addressed include SSRF in Azure SQL Database (CVE-2026-69502), incorrect authorization in Azure Arc (CVE-2026-69555), and argument injection in Azure Managed Instance for Apache Cassandra (CVE-2026-65770). SecurityWeek and Vypr Intelligence provide further details on the extensive patch release.
Cisco has addressed multiple vulnerabilities across its Crosswork and Secure Workload product lines, with five of these flaws receiving a CVSS score of 10.0. CVE-2026-20357 and CVE-2026-20358 are among the critical vulnerabilities patched, stemming from a comprehensive internal security review. These issues could allow attackers to execute code or elevate privileges. The Hacker News and SecurityWeek highlight the severity of these patches, emphasizing the need for prompt application to protect network infrastructure.
A cluster of critical vulnerabilities has been identified in Fabrik, a Joomla extension, versions prior to 4.7.3. These include missing ACL checks (CVE-2026-76607), path traversal via the image element (CVE-2026-76606), and remote code execution via the image element (CVE-2026-76605). Additionally, an unauthenticated remote code execution vulnerability exists via the PHP form element (CVE-2026-76604). Another critical vulnerability, CVE-2026-66915, allows unauthenticated attackers to execute arbitrary code using the calc plugin's ajax_calc feature. These flaws pose a significant risk to Joomla sites utilizing this extension.
Trendnet network devices are affected by several command injection vulnerabilities, including CVE-2026-77946 affecting the TEW-821DAP model. This critical vulnerability in the NTP Timezone Configuration Handler component allows for manipulation of the device's settings. Vypr Intelligence reports on these command injection flaws, underscoring the need for users to update their firmware to mitigate potential compromise.
Microsoft's August patch Tuesday addresses a critical elevation of privilege vulnerability in the Windows Common Log File System Driver, CVE-2021-43226. While this vulnerability has a high severity rating, its inclusion in the KEV catalog is not noted in the provided data. Users are advised to apply the latest Windows updates to protect against potential privilege escalation attacks.
Several other critical vulnerabilities have been disclosed, including an SSRF vulnerability in WordPress Mailgun for WordPress plugin (CVE-2026-78003), an arbitrary file upload/deletion vulnerability in Joomla's J-BusinessDirectory (CVE-2026-75949), and a vulnerability in Oracle Hyperion Financial Management (CVE-2026-70921). Additionally, a critical vulnerability in AWS's Neptune connector (CVE-2026-77810) could allow unauthorized access to sensitive properties. These vulnerabilities span various products and require prompt attention from affected organizations.