DevSecOps

Most important this week

Severity: HighAction: PatchExploitation: ExploitedCISA KEV

Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570

Microsoft Threat Intelligence examines CVE-2026-73570 exploitation in Zimbra, including observed attack paths, detection opportunities, and mitigation guidance.

Why it matters

CISA lists this as exploited in the wild. Unpatched Zimbra Collaboration Suite (ZCS) systems are exposed to active attacks now.

Patch

Apply the vendor's security update for Zimbra Collaboration Suite (ZCS).

All DevSecOps stories