Entra ID Remote Code Execution and Zimbra Command Injection Top August Patch List
# Entra ID Remote Code Execution and Zimbra Command Injection Top August Patch List
An RCE in Microsoft Entra ID with a CVSS 10.0 that's already being used in the wild. That pages me at 3am. It's not just about a single server going dark. When your identity provider is compromised, every SaaS app tied to that tenant becomes an open door.
Triage this week by exploitation status, not vendor stickers. I don't care if a vendor calls something "Critical" if there's no proof of it working outside a lab.
Start with the Entra ID flaw (CVE-2026-68820). It's a CVSS 10.0 and it's active. If you're running this, you aren't just patching a bug; you're stopping an attacker from owning your entire cloud identity. Right behind that is the GitLab vulnerability (CVE-2026-19478). It hit active exploitation within days of disclosure. That speed suggests the exploit script is already circulating in the right circles.
Then there is Zimbra. CVE-2026-73570 allows OS command injection. For federal agencies, the patch deadline is today, August 24. If you're a private shop running ZCS, ignore the government's calendar but don't ignore the bug. Command injection on a mail server is a direct path to credential harvesting and lateral movement.
The second tier is internet-facing assets where the exploit is likely imminent. Cisco has nine flaws in Crosswork and Secure Workload, five of which hit a CVSS 10.0. If these are sitting on your edge, they move to the front of the line. Also, look at the WordPress form plugin flaw (CVE-2026-15748). Just under 300,000 sites are exposed. That's a massive attack surface for any botnet looking to expand its footprint.
The rest can wait until tomorrow or next week. The MLflow SSRF and the TrueConf injections have deadlines hitting in early September. They're serious, but they aren't currently burning down the house.
Some admins will argue that their internal policy requires patching all CVSS 7.0+ bugs within a fixed window regardless of exploitation. That is how you end up with "patch fatigue" and missed detections. Following a rigid matrix instead of active telemetry is just administrative theater. It makes the compliance report look green while the attackers are already in the environment using an exploit that didn't hit the 7.0 threshold but provided exactly what they needed for dwell time.
We saw this pattern during the SolarWinds fallout. The industry spent months obsessing over software supply chain manifests while ignoring the second-order effects of identity compromise. This Entra ID situation is a rhyme of that era. The difference here is the velocity. We aren't talking about a slow burn; we're talking about an RCE in the core logic of the identity provider itself.
The downstream risk here isn't just your data. It's your suppliers and partners who trust your Entra ID tokens for federated access. If you're popped, you're potentially a vector into every vendor you have a B2B relationship with.
If you want to see where the real damage is happening, look at SafePal. Their recent breach exposed just under 40,000 customers. It's a reminder that while we fight over CVEs, some groups are just walking through the front door because of poor data hygiene.
Microsoft rolled out 22 fresh security patches recently. Don't try to eat them all at once. Focus on the Entra ID RCE and the IKE double free (CVE-2026-33824) first. The other 20 are mostly noise until proven otherwise.
If you're still seeing a sea of red on your dashboard, stop looking at the colors. Look at the KEV list. If it's not there and there's no public PoC, it doesn't get your time today.
I'll be watching for any sign of this Entra ID flaw being used to pivot into government cloud tenants. If that happens, the conversation shifts from patching to incident response across the entire sector.
◼
Sources
The reporting this analysis was built from. Follow the originals before acting on anything here.
- CISA orders urgent patching of actively exploited Zimbra flaw BleepingComputer
- Hackers claim massive data theft from thousands of students across 3,000 Italian schools - Escudo Digital Google News Security
- Iran-Linked Hackers Shut Down UK Power Plant for Four Days SecurityWeek
- Weekly Cyber Security Newsletter Bulletin – Entra ID RCE, Claude Code Ransomware, T-Mobile Cable, Azure... - CyberSecurityNews Google News Security
- Power Plants Under Siege: Defending Critical Infrastructure Against State-Sponsored Cyber Attacks - Cybersecurity Insiders Google News Security
- UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit The Hacker News
- Wall Street giant Apollo confirms personal data breach - Cybernews Google News Security
- Apollo Global reveals data breach after hackers target financial firms - VCCircle Google News Security