VYPR
AI Brief2026-08-23· generated Aug 23, 2026

Zimbra, Microsoft Entra ID Exploited; Critical Flaws Disclosed

Zimbra and Microsoft Entra ID vulnerabilities are actively exploited, with critical flaws in both platforms leading to RCE and privilege escalation.

Zimbra Collaboration (ZCS) versions prior to 10.1.20 are affected by a remote code execution vulnerability (CVE-2026-73570) when the optional zimbra-snmp package is installed and SNMP notifications are enabled. The flaw stems from improper sanitization of untrusted input within SNMP notifications, allowing attackers to execute arbitrary code. This vulnerability has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog and is actively being exploited in the wild, as reported by Vypr Intelligence and The Hacker News.

Microsoft has released patches for a significant number of vulnerabilities, including several critical flaws across its Azure services and other products. Notably, CVE-2026-69836, a critical vulnerability in Microsoft Entra ID, is being actively exploited and allows for remote code execution. Other critical vulnerabilities include server-side request forgery (SSRF) in Azure SQL Database (CVE-2026-69502) and Microsoft Exchange Online (CVE-2026-65801), deserialization of untrusted data in Microsoft Entra ID (CVE-2026-69836), and improper authorization in Azure Arc (CVE-2026-69555). These flaws, detailed in advisories from SecurityWeek and Vypr Intelligence, carry a CVSS score of 10.0 and pose a significant risk to organizations utilizing these services.

Cisco has addressed multiple vulnerabilities in its Crosswork and Secure Workload products, with five of them rated critical and carrying a CVSS score of 10.0. These include CVE-2026-20358 and CVE-2026-20357, which are part of a software hardening release. While the specific details of the exploits are not fully disclosed, the high severity indicates potential for significant impact, such as remote code execution or elevated privileges. The Hacker News and SecurityWeek reported on these patches, emphasizing Cisco's proactive approach to security.

Several critical vulnerabilities have been disclosed in Joomla extensions, including arbitrary file upload and path traversal in J-BusinessDirectory (CVE-2026-75949) and remote code execution in Fabrik (CVE-2026-66915). The J-BusinessDirectory vulnerability allows attackers to upload or remove files by exploiting a path traversal flaw, while the Fabrik vulnerability enables unauthenticated attackers to execute arbitrary code via its ajax_calc feature. These issues highlight the importance of keeping third-party extensions updated to prevent potential compromises.

Trendnet's TEW-821DAP router is affected by a critical vulnerability (CVE-2026-77946) in its NTP Timezone Configuration Handler. This flaw, located in the /cgi-bin/apply_time.cgi file, allows for command injection due to insufficient validation of input. Vypr Intelligence reported on this vulnerability, noting its potential to allow attackers to execute arbitrary commands on the affected device.

WordPress sites using the Mailgun for WordPress plugin are vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to 2.2.0 (CVE-2026-78003). The vulnerability arises from insufficient input validation in the add_list() function, which could allow an attacker to access internal resources or interact with unintended services. This highlights the ongoing need for vigilance in updating plugins to mitigate such risks.

SPIP versions prior to 4.4.20 contain a critical vulnerability (CVE-2026-77647) that allows unauthenticated remote attackers to execute arbitrary code. This flaw, which has reportedly been exploited in the wild, is related to the incorrect handling of <?php blocks and var_export's behavior with certain inputs. The vulnerability underscores the importance of timely patching for web content management systems.

Oracle Hyperion Financial Management (HFM) version 11.2.25.0.000 is susceptible to a critical vulnerability (CVE-2026-70921) in its security component. This easily exploitable flaw allows an unauthenticated attacker with network access to compromise the system, potentially leading to unauthorized access or control.

AWS users leveraging the Neptune connector with Athena Federated Query are at risk due to a vulnerability (CVE-2026-77810) in the Neptune connector. A user with access to Neptune could potentially gain access to properties in the Lambda function providing compute for the connector, leading to privilege escalation. Users are advised to upgrade to the latest version of aws-athena-query-federation to remediate this issue.

Microsoft Windows Common Log File System Driver is affected by an elevation of privilege vulnerability (CVE-2021-43226). While this vulnerability has a lower EPSS score, it remains a potential avenue for attackers to escalate privileges on compromised systems.

Cisco has also released patches for nine Crosswork and Secure Workload vulnerabilities, including CVE-2026-20357 and CVE-2026-20358, as part of its ongoing security efforts. These patches are crucial for maintaining the integrity and security of Cisco's network management and workload security solutions.

Synthesized by Vypr AI