Russian hackers exploit an unpatched Zimbra zero-day
The lead today is active exploitation, not a theoretical bug. Help Net Security and Dark Reading both report that Russian actors, tracked as Laundry Bear, are exploiting an unpatched Zimbra flaw, CVE-2025-66376, to steal email from US and Ukraine targets. This is a zero-day used in the wild, which puts it in the patch-now category rather than the patch-when-convenient one.
If you run Zimbra anywhere, treat mail servers as a priority. Confirm your version, apply the vendor fix as soon as it is available, and review mailbox access and forwarding rules for signs of theft. Email servers are a favorite target because they hold exactly what an intelligence operation wants.
ColdFusion CVE-2026-48282 and the exploited-CVE picture
No new CISA KEV additions came through since 2026-07-23, but the exploited list still has hot movers worth your attention. Adobe ColdFusion path traversal CVE-2026-48282 is on CISA KEV, carries a CVSS of 10, and has an EPSS score of 0.99, which means exploitation is close to certain. If you have any internet-facing ColdFusion, patch it before anything optional on your list.
Two more are KEV-listed and moving. Langflow CVE-2026-55255, an authorization bypass through a user-controlled key, is Critical at CVSS 9.9. Alcatel OmniPCX Enterprise CVE-2007-3010, an older remote code execution flaw, still shows an EPSS near 0.98, a reminder that legacy telephony gear stays exploited long after everyone forgets it exists.
On the Microsoft side, SharePoint remote code execution CVE-2026-50522 (CVSS 9.8) and Exchange spoofing CVE-2026-42897 remain KEV-listed. SharePoint and Exchange are internet-exposed by design in many tenants, so verify these are closed even if you patched weeks ago.
What the trusted press adds
Rapid7 continues to track Check Point SmartConsole authentication bypass CVE-2026-16232 as exploited in the wild, alongside related Check Point flaws. Qualys published details on RefluXFS, a Linux kernel local privilege escalation to root in XFS tracked as CVE-2026-64600, which matters for any Linux estate where an attacker who lands a foothold wants to become root.
CISA also released a batch of ICS advisories on 2026-07-23 covering Panduit IntraVUE, Johnson Controls C-CURE 9000 and Victor, Johnson Controls XAAP Android, and MZ Automation lib60870 and libIEC61850. If you run operational technology, pull those into your review. Australia's ASD separately warned of an ongoing Russian phishing campaign, which lines up with the Zimbra activity above.
Do this first
Priorities for the day, grounded in what is being exploited right now:
- Patch or mitigate Zimbra against CVE-2025-66376 and hunt for stolen-mail indicators, since this is an active zero-day.
- Patch internet-facing Adobe ColdFusion for CVE-2026-48282; a CVSS 10 with EPSS 0.99 on the KEV list is as urgent as it gets.
- Confirm SharePoint CVE-2026-50522 and Exchange CVE-2026-42897 are closed across all hosts.
- Address Langflow CVE-2026-55255 and legacy Alcatel CVE-2007-3010 if either is in your estate.
- Review the 2026-07-23 CISA ICS advisories if you run Panduit or Johnson Controls gear.
Check your own state
To see which of these are still open in your environment, the free Microsoft Patch Tracker from Siemserva by Senserva ranks open Microsoft patches by CISA KEV, EPSS, and ransomware linkage, and the non-Microsoft exploited-CVE tracker follows KEV additions daily. For a full look at your Microsoft 365, Intune, Defender, and Entra ID posture, Siemserva offers three free unlimited audits after a one-time registration.
Sources
- Help Net Security: Russian hackers exploit unpatched Zimbra servers to steal emails (2026-07-24)
- Dark Reading: Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets (2026-07-23)
- Rapid7: CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild (2026-07-23)
- Qualys: RefluXFS: A Linux Kernel Local Privilege Escalation to Root in XFS (CVE-2026-64600) (2026-07-22)
- defenceconnect.com.au: ASD, National Cyber Security Coordinator warn of ongoing Russian phishing campaign - defenceconnect.com.au (2026-07-24)
- CISA Cybersecurity Advisories: Panduit IntraVUE (2026-07-23)
- CISA Cybersecurity Advisories: Johnson Controls C-CURE 9000 and Victor application server (2026-07-23)
Written by Senserva Trustworthy AI from the day's live partner feeds (CISA KEV, MSRC, FIRST EPSS, and the trusted press list), validated so every CVE, KB, and reference resolves to that data. The sources behind every feed, and their terms, are on our Data sources & thanks page. Facts as of 2026-07-25.