U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog

2026-08-22T08:51:35Z64dfcc33c45526958ba9f2a452682df60440bd7e754e0023a4bd2ca897c29d2c
CVE-2026-19478CVE-2026-73570Android malwareCISA KEVCiscoCl0pFlexPLMGitLabICSOAuth abusePTC WindchillRussia-linked espionageSCADASiemens S7 PLCTrueConf ServerWhatsAppZimbra Collaboration Suiteactive exploitationcritical infrastructuremobile banking fraudphishingransomwareunauthenticated RCEzero-day

What happened

Security Affairs reports multiple significant cybersecurity developments, including active exploitation of critical vulnerabilities in Zimbra Collaboration Suite (CVE-2026-73570) and GitLab (CVE-2026-19478), CISA KEV additions affecting Zimbra and TrueConf Server, mass exploitation claims involving PTC Windchill/FlexPLM by Cl0p, Russia-linked phishing and OAuth abuse campaigns, Android malware with offline Bluetooth-based data theft capabilities, and active attacks against Siemens S7 PLCs in critical infrastructure. Cisco also disclosed six CVSS 10.0 flaws, though no exploitation was reported.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
64dfcc33c45526958ba9f2a452682df60440bd7e754e0023a4bd2ca897c29d2c
Enrichment time
2026-08-22T08:51:35Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog · Baitaphish