Vulnerabilities
Actively exploited vulnerabilities (CISA KEV) in mail servers, mail gateways, and webmail: affected versions, updates, workarounds, and compromise assessment.
NewCVE-2026-73570: Zimbra Command Injection via SNMP Is Being Exploited—Update to 10.1.20 and Check for Compromise
A crafted email is all it takes: On Zimbra servers with the zimbra-snmp package and SNMP notifications enabled, attackers can execute commands as the zimbra user without authentication (CVE-2026-73570, CVSS 8.9). The vulnerability is being exploited and was fixed in 10.1.20. Update, apply the workaround until then, and check for web shells and persistence.
NewCVE-2026-76461: Cisco Secure Email Gateway SQL Injection Is Being Exploited—Update and Check for Compromise
A specially crafted email is all it takes: via an SQL injection in AsyncOS, attackers can execute commands with root privileges on Cisco Secure Email Gateway (CVE-2026-76461, CVSS 9.8). The vulnerability is being exploited, and no workaround is available. Updating to a fixed version and checking for compromise are required.
NewCVE-2026-104286: FortiMail Zero-Day Is Being Exploited - Workaround and Compromise Assessment
Fortinet reports a critical, actively exploited path traversal vulnerability in FortiMail 7.2 through 8.0 (CVE-2026-104286, CVSS 9.8). A patch is not yet available. The workaround disables IBE or blocks Internet access to the management interface; indicators for assessing compromise are also available.
Kiteworks: Vendor Recommends Shutdown on September 26—What Is Known So Far
Kiteworks asked its customers by email to shut down all systems on Saturday, September 26, 2026, from 4:00 a.m. to 10:00 a.m. The reason is a warning from law enforcement agencies about a possible attack. Since September 27, the recommendation has been lifted; there is no CVE or new patch. TotemoMail is not affected.
CVE-2026-62911: Why 85 Percent of On-Premises Exchange Servers Are Vulnerable and What Is Technically Behind It
The BSI reports that around 85 percent of on-premises Exchange servers in Germany are vulnerable to CVE-2026-62911. This article explains the vulnerability technically: MRSProxy, missing Channel Binding, NTLM relay, and Orange Tsai’s Pwn2Own chain, along with context for the figures and the specific recommended actions.