Posts Tagged ‘command-injection’
Zimbra Command Injection Vulnerability Actively Exploited
A Zimbra command injection vulnerability is under confirmed active exploitation against on-premises mail servers, and CISA’s federal remediation deadline of August 24 has already passed. Tracked as CVE-2026-73570, the flaw lets an unauthenticated attacker execute arbitrary shell commands on any unpatched Zimbra Collaboration Suite instance with SNMP notifications enabled — a configuration many administrators never…
Read MoreProgress LoadMaster CVE-2026-8037: 792 Attacks Logged
Progress LoadMaster CVE-2026-8037, a CVSS 9.6 unauthenticated command-injection flaw, has already been hit with 792 confirmed exploitation attempts from 65 IP addresses over 41 days — and CISA added it to its Known Exploited Vulnerabilities catalog on August 7. If your load balancer is still running an unpatched build, the scanning has almost certainly already…
Read MoreArista VeloCloud Orchestrator CVE-2026-16812 Exploited
Arista VeloCloud Orchestrator CVE-2026-16812 is a maximum-severity, unauthenticated command injection flaw under active exploitation right now, and it hands an attacker control of an entire SD-WAN fabric from a single unpatched management console. CISA added it to the Known Exploited Vulnerabilities catalog on July 27, with a federal patch deadline of July 30. If your…
Read More
