U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog
2026-08-22T08:51:35Z•64dfcc33c45526958ba9f2a452682df60440bd7e754e0023a4bd2ca897c29d2c
CVE-2026-19478CVE-2026-73570Android malwareCISA KEVCiscoCl0pFlexPLMGitLabICSOAuth abusePTC WindchillRussia-linked espionageSCADASiemens S7 PLCTrueConf ServerWhatsAppZimbra Collaboration Suiteactive exploitationcritical infrastructuremobile banking fraudphishingransomwareunauthenticated RCEzero-day
What happened
Security Affairs reports multiple significant cybersecurity developments, including active exploitation of critical vulnerabilities in Zimbra Collaboration Suite (CVE-2026-73570) and GitLab (CVE-2026-19478), CISA KEV additions affecting Zimbra and TrueConf Server, mass exploitation claims involving PTC Windchill/FlexPLM by Cl0p, Russia-linked phishing and OAuth abuse campaigns, Android malware with offline Bluetooth-based data theft capabilities, and active attacks against Siemens S7 PLCs in critical infrastructure. Cisco also disclosed six CVSS 10.0 flaws, though no exploitation was reported.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 64dfcc33c45526958ba9f2a452682df60440bd7e754e0023a4bd2ca897c29d2c
- Enrichment time
- 2026-08-22T08:51:35Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.