Exchange Authentication Bypass Vulnerability Now Exploitable

A public exploit for an Exchange authentication bypass vulnerability is live, and 85% of German on-prem servers remain unpatched, BSI warns.

A working exploit for an Exchange authentication bypass vulnerability is now public on GitHub, and heise.de reports that roughly 85% of on-premises Exchange servers in Germany remain vulnerable three weeks after Microsoft shipped a fix. The catch: for organizations still running Exchange 2016 or 2019, that fix is locked behind Microsoft’s paid Extended Security Update…

Read More

Identity Theft in Germany: What SMEs Need to Know

Identity theft and stolen credentials drive most cybercrime in Germany

Germany’s cybercrime problem has a number attached to it: an estimated €202.4 billion in damage to the German economy for the 2025 reporting period, around 4.5 percent of GDP, according to the Federal Criminal Police Office’s (BKA) latest Bundeslagebild Cybercrime report. Behind much of that damage sits a quieter but persistent issue: identity theft in…

Read More

Zimbra Command Injection Vulnerability Actively Exploited

A Zimbra command injection vulnerability is under active exploitation against on-premises mail servers; the CISA federal deadline already passed.

A Zimbra command injection vulnerability is under confirmed active exploitation against on-premises mail servers, and CISA’s federal remediation deadline of August 24 has already passed. Tracked as CVE-2026-73570, the flaw lets an unauthenticated attacker execute arbitrary shell commands on any unpatched Zimbra Collaboration Suite instance with SNMP notifications enabled — a configuration many administrators never…

Read More

Microsoft Entra ID RCE Vulnerability Exploited

A maximum-severity Microsoft Entra ID RCE vulnerability was already being exploited before Microsoft's August 20 disclosure, and no customer patch exists.

Microsoft disclosed a maximum-severity Microsoft Entra ID RCE vulnerability on August 20, 2026, and confirmed the flaw was already being exploited in the wild before the advisory went public. CVE-2026-69836 carries a CVSS score of 10.0, needs no authentication and no user interaction, and sits in the identity backbone underneath Microsoft 365, Azure AD sign-in,…

Read More

VMware vCenter CVE-2026-59310: Germany Hit Hardest

VMware vCenter CVE-2026-59310, a CVSS 9.8 flaw, is under active exploitation in 47 countries — Germany is hit hardest. What to do now.

VMware vCenter CVE-2026-59310, a maximum-severity path-traversal vulnerability scoring 9.8 on CVSS, is being actively exploited across 47 countries — and Germany is the single most-affected country of all of them. German incident-response firm QUIRSO uncovered the campaign live during an IR engagement, tracing 361 distinct victim IP addresses back to a directory-traversal flaw in vCenter’s…

Read More