started · updated
Microsoft and Zimbra address critical security vulnerabilities
Microsoft has released a patch for a maximum-severity security flaw in its Entra ID cloud-based identity and access management service. The vulnerability, tracked as CVE-2026-69836, carries a CVSS score of 10.0 and allows for remote code execution through the deserialization of untrusted data. While initial reports suggested the flaw was being exploited in the wild, Microsoft later clarified that the vulnerability had not been exploited.
Separately, a critical vulnerability in the Zimbra Collaboration Suite, identified as CVE-2026-73570, is reportedly being actively exploited. The flaw allows unauthenticated attackers to execute operating system commands by sending crafted SMTP requests to servers with SNMP notifications enabled. Successful exploitation provides attackers with the privileges of the zimbra user, potentially allowing them to access emails, credentials, and internal networks.
Entities
CERT Polska · Entra ID · Microsoft · Zimbra Collaboration Suite