Microsoft issued an out-of-band Exchange Server fix for CVE-2026-96940, a bug letting signed-in attackers read colleagues' mail and attachments. The company expects the flaw to be consistently exploitable, so on-premises admins have good reason to install it ahead of the next maintenance window.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence50
Microsoft says attackers are using CVE-2026-73570 to run commands on Zimbra mail servers with one crafted email and no login. Zimbra shipped the fix in 10.1.20 on July 20, 24 days before disclosure, so anyone who waited for the advisory to patch was already late.
Perspective Coverage
4 publishers
- Builder
- Builder 21%
- Operator
- Operator 68%
- Investor
- Investor 11%
Reality
- Evidence80
- Adoption40
- Hype gap+5
- Incentives
- Insufficient
- Confidence75
The release Zimbra rates High severity closes a command injection in SNMP monitoring plus four Classic Web Client scripting bugs. Sites that acted on the June advisory still have work queued.
Publishers:blog.zimbra.com · wiki.zimbra.com
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives40
- Confidence60
Gitea shipped a fix for CVE-2026-60004 on July 27 and CISA gave federal agencies until August 28, yet a month later Shadowserver still counts 8,393 exposed instances, and on shipped defaults the bug needs no credentials.
Perspective Coverage
7 publishers
- Builder
- Builder 22%
- Operator
- Operator 67%
- Investor
- Investor 11%
Reality
- Evidence62
- Adoption40
- Hype gap+20
- Incentives
- Insufficient
- Confidence58
Rapid7's research with Zimbra turned up more than 50 vulnerabilities, several of which let an attacker send mail as another user with no password involved. The operational item today is CVE-2026-73570, the SNMP command injection CISA gave federal agencies three days to fix.
Reality
- Evidence55
- Adoption60
- Hype gap+25
- Incentives78
- Confidence55