Week in review: Compromised Zimbra servers, previously patched Citrix NetScaler flaw exploited
Reported exploitedZimbraShinyHuntersCitrix NetScalerOur summary
The Shadowserver Foundation has reported that at least 274 internet-facing Zimbra instances have been compromised via CVE-2026-73570, highlighting the urgency of applying recent security updates. Simultaneously, CISA confirmed active exploitation in the wild of CVE-2026-8452, a flaw previously patched in Citrix NetScaler ADC and Gateway products. These developments underscore the critical need for organizations to verify their patch levels across email and load-balancing infrastructure.
Help Net Security publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.