Tech News
← Home  ·  All topics

Cve

75 GoKawiil briefs on this topic

CISA gives federal agencies 3 days to patch critical Zimbra flaw

CISA has issued an emergency directive requiring federal agencies to fix a Zimbra vulnerability, tracked as CVE-2026-73570, within just three days. The flaw is severe enough that exploitation could give an attacker complete control over a victim's email and communications.

Attackers actively exploit auth-bypass flaws in miniOrange SSO plugin for WordPress

Security researchers say hackers are exploiting two chained vulnerabilities, CVE-2026-61979 and CVE-2026-15981, in the miniOrange SAML 2.0 Single Sign On plugin to forge SAML responses and log into WordPress sites as administrators. The plugin, made by Xecurify, lets sites authenticate through identity providers like Microsoft Entra ID, Okta, Google Workspace or OneLogin, and comes in a free version plus six paid editions used by roughly 30,000 customers.

CISA gives federal agencies 3 days to patch actively exploited Zimbra RCE bug

CISA has ordered federal civilian agencies to fix CVE-2026-73570, a Zimbra Collaboration Suite flaw allowing unauthenticated attackers to run arbitrary commands via crafted SMTP requests when SNMP notifications are enabled. Zimbra released a fix in version 10.1.20 on July 20, but CERT Polska flagged active exploitation last week, and Shadowserver has already identified over 270 compromised Zimbra servers among more than 12,000 exposed online.