Skip to content

Topic

Email and collaboration server security

Security defects and hardening in self-hosted mail and groupware platforms.

Current stories

security1 publisher

Out-of-band Exchange Server patch closes a flaw that exposes colleagues' mail to signed-in attackers

Microsoft issued an out-of-band Exchange Server fix for CVE-2026-96940, a bug letting signed-in attackers read colleagues' mail and attachments. The company expects the flaw to be consistently exploitable, so on-premises admins have good reason to install it ahead of the next maintenance window.

Reality

Evidence55
Adoption
Insufficient
Hype gap0
Incentives
Insufficient
Confidence50
security4 publishers

Crafted emails give attackers shells on Zimbra servers running SNMP notifications

Microsoft says attackers are using CVE-2026-73570 to run commands on Zimbra mail servers with one crafted email and no login. Zimbra shipped the fix in 10.1.20 on July 20, 24 days before disclosure, so anyone who waited for the advisory to patch was already late.

Perspective Coverage

4 publishers
Builder
Builder 21%
Operator
Operator 68%
Investor
Investor 11%

Reality

Evidence80
Adoption40
Hype gap+5
Incentives
Insufficient
Confidence75
security7 publishers

Default self-registration hands unauthenticated attackers Gitea's exploited RCE on 8,393 servers

Gitea shipped a fix for CVE-2026-60004 on July 27 and CISA gave federal agencies until August 28, yet a month later Shadowserver still counts 8,393 exposed instances, and on shipped defaults the bug needs no credentials.

Perspective Coverage

7 publishers
Builder
Builder 22%
Operator
Operator 67%
Investor
Investor 11%

Reality

Evidence62
Adoption40
Hype gap+20
Incentives
Insufficient
Confidence58