VYPR
AI Brief2026-08-25· generated Aug 25, 2026

Zimbra RCE Exploited; Critical Flaws Hit Joomla, IoT Devices

Zimbra RCE vulnerability actively exploited and added to CISA KEV; critical flaws found in Joomla extensions and IoT devices.

Zimbra Collaboration Suite (ZCS) versions prior to 10.1.20 are affected by a critical remote code execution vulnerability (CVE-2026-73570) when the optional zimbra-snmp package is installed and SNMP notifications are enabled. The flaw stems from improper sanitization of untrusted input, allowing unauthenticated attackers to achieve code execution. This vulnerability has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog and is reportedly being actively exploited in the wild, with multiple security outlets reporting on ongoing attack campaigns targeting Zimbra servers. Administrators are urged to update to ZCS 10.1.20 or later immediately to mitigate this risk.

A batch of critical vulnerabilities has been disclosed in Joomla extensions, primarily affecting the Fabrik component by fabrikar.com. Versions prior to 4.7.2 are susceptible to several issues, including missing Access Control List (ACL) checks in the download element (CVE-2026-76607), path traversal via the image element (CVE-2026-76606), and remote code execution (RCE) through both the image element (CVE-2026-76605) and an unauthenticated RCE via the PHP form element (CVE-2026-76604). These flaws, carrying CVSS scores up to 10.0, pose a significant risk to Joomla-based websites, potentially allowing attackers to compromise the underlying server. Users should update Fabrik to version 4.7.2 or newer.

Several critical vulnerabilities have been identified across various IoT and network devices. Trendnet TEW-821DAP (v2.2.01b05) is impacted by a command injection flaw in its NTP Timezone Configuration Handler (CVE-2026-77946). Additionally, Comfast CF-N1-S (v2.6.0.1) suffers from command injection vulnerabilities in its Web Management interface related to NTP timezone settings (CVE-2026-78050, CVE-2026-77683). Netis NC63 firmware (up to V3.0.0.3327) contains a stack-based buffer overflow in its IP filter list configuration (CVE-2026-76071), and UTT HiPER 1250GW (up to 3.2.7-210907-180535) has an HTTP Request Handler vulnerability (CVE-2026-78169). These flaws often allow for unauthenticated remote code execution or command injection, highlighting the need for prompt patching of network-attached devices.

WordPress sites are facing multiple critical vulnerabilities across several plugins. Unauthenticated PHP object injection affects FreightCo (<= 1.1.15) (CVE-2026-66650), while unauthenticated privilege escalation is possible in Jawn (<= 1.4.2) (CVE-2026-66648) and Affiliate Pro (<= 8.9.1) (CVE-2026-32558). Digits (<= 9.2) also suffers from an unauthenticated privilege escalation vulnerability (CVE-2026-28165). Furthermore, WP Cafe Pro ( < 3.0.15) has an unauthenticated local file inclusion flaw (CVE-2026-66587). These vulnerabilities, many with high CVSS scores, could allow attackers to gain significant control over WordPress installations. Users should update these plugins to the latest available versions.

Oracle Hyperion Financial Management (HFM) version 11.2.25.0.000 is affected by a critical vulnerability (CVE-2026-70921) that allows unauthenticated attackers with network access to compromise the security component. This easily exploitable flaw could lead to unauthorized access or control over sensitive financial data. Prompt patching or applying vendor mitigations is crucial for organizations using this product. Additionally, a privilege escalation vulnerability in StackGres operator (CVE-2026-78155) allows low-privilege users to gain administrator privileges within the database environment, underscoring the importance of secure configuration and timely updates for database management systems.

Synthesized by Vypr AI
Zimbra RCE Exploited; Critical Flaws Hit Joomla, IoT Devices · VYPR