Hackers Target Zimbra Servers in Active Exploitation Campaign
2026-08-21T07:23:59Z•1ef3e51be6c012cc877b687da43aa53f0116e101c2bc1a698bf1127fba501835
CVE-2026-19478CVE-2026-73570AtlassianCiscoCitrix NetScalerDahuaGitLabIP-camerasIoTMLflowRussiaSplunkUkraineZimbraactive-exploitationauthentication-bypasscloud-credential-theftdata-exposurepath-traversalprivilege-escalationrcevulnerabilityzero-day
What happened
SecurityWeek RSS feed reports active exploitation and critical vulnerabilities affecting Zimbra Collaboration, MLflow, GitLab, Citrix NetScaler, Cisco products, Atlassian, and Splunk. Threat activity also includes a campaign compromising approximately 14,000 Dahua IP cameras. The most urgent items are the actively exploited Zimbra and GitLab flaws, MLflow exploitation for cloud credential theft, and the unauthenticated Citrix NetScaler authentication bypass.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- 1ef3e51be6c012cc877b687da43aa53f0116e101c2bc1a698bf1127fba501835
- Enrichment time
- 2026-08-21T07:23:59Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.