decrypted · 24 august 2026 · vulnerabilities and patching · ai and llm security
The Zimbra flaw CISA gave three days to fix, and the feature that opened the door
Zimbra's mail and collaboration platform runs inboxes for governments and businesses worldwide, and as of today US federal agencies had until close of play to patch one of them: an unauthenticated flaw that lets an attacker run commands on the server without so much as a password. CISA added it to its Known Exploited Vulnerabilities catalogue on 21 August with a three day deadline, after Poland's national CERT caught it being exploited in the wild days earlier. Roughly 4,400 Zimbra servers are reachable from the internet in Europe alone, and nobody has published how many are patched.
A monitoring feature that talks back
The flaw, CVE-2026-73570, sits in the optional zimbra-snmp package, the part of Zimbra that raises alerts if something on the server misbehaves. It relies on a background watchdog process that runs by default on most installations, whether or not anyone actually uses SNMP monitoring. That process does not properly clean up the text it is handed before acting on it. Send it a crafted request over SMTP, the same channel any mail server has to accept from the open internet, and it will run whatever operating system command is hidden inside, as the Zimbra user, no login required.
It is a smoke alarm wired into the front door lock: useful when it works as intended, but nobody checked whether a stranger shouting through the letterbox could trigger it too. Zimbra shipped the fix, version 10.1.20, on 20 July. CERT Polska's warning that attackers were actively exploiting it followed on 17 August, almost a month later, leaving a wide window in which the patch existed and most servers still did not have it.
The Secure by Design lesson
The interesting failure is not the missing input sanitisation, though there is plenty of that. It is that a monitoring feature most administrators never asked for, and may not know is running, was left switched on by default, wired to a process with enough privilege to execute system commands, and reachable from a protocol the server must expose to the world. Secure by Design asks vendors to ship the low risk configuration as standard and make the riskier one an explicit choice. Here the reverse happened.
For UK organisations running Zimbra, or any collaboration platform, this week's task is not just patching. It is asking what else ships enabled by default that nobody actually uses, and whether it is reachable from the internet-facing side of the service. Zimbra has form: Russia-linked groups including APT28, APT29 and Winter Vivern have previously exploited flaws in the platform against government and NATO-adjacent targets, so a patch cycle measured in weeks, not CISA's three days, is a real gap.
Also this week
The NSA, FBI, CISA and two other US agencies issued a joint advisory on 19 August describing an "active threat" in which attackers use AI to write Python scripts that talk directly to Siemens S7 series PLCs, the controllers behind water, energy and manufacturing processes, disguised as legitimate monitoring software. The libraries the scripts use are not new; what AI has cut is the expertise and time needed to build them, exactly the "forced correction" the NCSC has been warning about all year. It arrives in the same week UK readers learned that Iranian-linked attackers kept a power plant offline for four days, a reminder that the barrier to reconnaissance against UK operational technology is getting lower.
Microsoft, meanwhile, had to correct its own homework. It patched a maximum severity, CVSS 10.0 remote code execution flaw in Entra ID, the identity service behind Microsoft 365 and Azure sign-in for a huge share of UK organisations, and initially told customers it had been exploited in the wild. On 24 August it walked that back: its own engineers found the bug internally, and there was no evidence of exploitation after all. No customer action was needed either way, since Microsoft fixed it server side. A small story, but a useful one: even a vendor's own "was this exploited" field can change between one version of an advisory and the next.
Sources
- Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution
- U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog
- Critical Zimbra RCE flaw now actively exploited in attacks
- NSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technology
- US warns of AI-powered attacks on Siemens PLCs in critical infrastructure
- Microsoft rolls out 22 fresh security patches
If you want a second pair of eyes on your own attack surface, get in touch.
More like this
- A crafted email is all it takes to root Cisco's mail gateway 15 september 2026
- A Russian spy operation had Claude rewrite its own malware after getting caught 13 september 2026
- The phone call that gets past your passkey 12 september 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.
Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.