Contacts
Book a Meet
Close

Contacts

Bulgaria, Kavarna
Saudi Arabia, Riyadh

+359 875 328030

sales@diamatix.com

Contacts

Bulgaria, Kavarna
Saudi Arabia, Riyadh

+359 875 328030

sales@diamatix.com

80191

Actively Exploited Gitea and Zimbra Vulnerabilities Highlight Risk in Public-Facing Development and Email Systems

What Is Confirmed

CISA added two actively exploited vulnerabilities to its KEV (Known Exploited Vulnerabilities) catalog: CVE-2026-60004 in Gitea and CVE-2026-73570 in Zimbra Collaboration.

Both issues are operationally important because they affect systems that are often reachable from the internet. Gitea is used for code management, repositories, code review and developer collaboration. Zimbra is used for email and collaboration.

When such systems are public-facing, vulnerabilities in them do not remain isolated technical issues. They may become entry points into code, internal integrations, email communication, accounts, attachments and sensitive business data.

What Is Known About Gitea

CVE-2026-60004 affects Gitea versions prior to 1.27.1. Gitea’s official advisory describes the vulnerability as remote command execution through abuse of the diffpatch function and the Git hook mechanism.

In practice, an attacker with write access to a repository can execute commands as the operating system user running Gitea. If open registration is enabled, an external visitor may create an account, create a repository and obtain the required permissions to start the attack.

This is not just a “code platform vulnerability.” Gitea often contains source code, configurations, scripts, internal documentation, tokens, links to other systems and automated processes. A compromise may therefore affect not only the server itself, but also the software development process.

What Is Known About Zimbra

CVE-2026-73570 affects Zimbra Collaboration versions prior to 10.1.20. The vulnerability is related to command injection during processing of SNMP (Simple Network Management Protocol) notifications when that functionality is enabled.

According to NVD, an unauthenticated attacker can send specially crafted SMTP (Simple Mail Transfer Protocol) requests that may lead to command execution as the zimbra user.

BleepingComputer reports that Shadowserver saw 274 potentially compromised Zimbra instances while scanning for exploitation artifacts on 22 August. Shadowserver also reported thousands of unpatched Zimbra instances, but noted that this does not automatically mean they are all exploitable because the issue depends on a specific configuration.

Why These Two Vulnerabilities Belong Together

At first glance, Gitea and Zimbra are different systems. One is connected to software development, the other to email. The shared risk is that both often sit close to sensitive information and workflows.

Gitea can expose code, configurations, scripts and deployment processes. Zimbra can expose mailboxes, internal communication, attachments and user interactions.

For attackers, these systems are valuable not only because they can be compromised, but because they contain context. Code shows how an organization works. Email shows who communicates with whom, what decisions are being made and where the attack can continue.

The Operational Signal

When CISA adds a vulnerability to the KEV catalog, the “will it be used” phase is over. The practical question becomes: do we have the affected system, is it exposed and are there signs of exploitation.

For Gitea, this means checking not only the version, but also open registration, public repositories, write permissions, automations and links to other systems.

For Zimbra, this means checking not only whether version 10.1.20 has been applied, but also whether SNMP notifications are enabled, whether suspicious files exist, whether unexpected restarts occurred, whether unusual requests appear and whether commands were executed as the zimbra user.

What Organizations Should Check

Practical checks:

  • whether Gitea or Zimbra instances are reachable from the internet;
  • whether Gitea versions prior to 1.27.1 are in use;
  • whether Zimbra Collaboration versions prior to 10.1.20 are in use;
  • whether open registration is enabled in Gitea;
  • which users have repository write permissions;
  • whether suspicious Git hooks, new repositories or unexpected code changes exist;
  • whether SNMP notifications are enabled in Zimbra;
  • whether files created by the zimbra user appear in unusual directories;
  • whether there are signs of mailbox access, message downloads or forwarding-rule changes;
  • whether logs are sufficient for retrospective review.

The key question is not only whether a patch exists. It is whether the system was exposed before the update and whether the organization can prove what happened.

DIAMATIX Comment

From the DIAMATIX perspective, these vulnerabilities show why development and email systems must be treated as critical assets.

A code server and an email server hold different types of information, but both can give an attacker a path to deeper access. In Gitea, the risk may extend to source code, secrets, deployment processes and internal services. In Zimbra, the risk may extend to communication, documents, contacts and follow-on phishing.

SOC (Security Operations Center) and MDR (Managed Detection and Response) processes should connect vulnerabilities with real exposure: which server is reachable, which version it runs, what permissions exist, what changed and whether behavior indicates an existing compromise.

For actively exploited vulnerabilities, fast updating is only the first step. After that comes verification: is there persistence, code change, data exfiltration, new mail rules or evidence that the attacker already moved toward another system.

Questions for CISO, IT and DevOps Teams

  • Which code and email systems are reachable from the internet?
  • Which of them are affected by actively exploited vulnerabilities?
  • Do we have a clear owner for each such system?
  • How do we monitor open registration, write permissions and repository changes?
  • How do we detect suspicious Git hooks or deployment process changes?
  • How do we check whether Zimbra was used before updating?
  • Can we see unusual files, restarts and executed commands?
  • Do we have a process for isolation, analysis and recovery of these systems?

The practical takeaway: public-facing developer and email systems are not auxiliary infrastructure. They are part of the attack surface and should be monitored as critical business systems.

 

Check whether your public-facing systems are updated and verified

DIAMATIX can help assess exposure, vulnerabilities, logs and response readiness for actively exploited vulnerabilities in development systems, email and business applications.

Request an exposure and response readiness review with DIAMATIX.
Trusted · Innovative · Vigilant


Sources

  • CISA. Known Exploited Vulnerabilities Catalog — CVE-2026-60004 and CVE-2026-73570.
  • Canadian Centre for Cyber Security. Gitea Security Advisory AV26-845.
  • Gitea. Remote Code Execution via diffpatch Git Hook Installation.
  • Canadian Centre for Cyber Security. Zimbra Security Advisory AV26-816.
  • NVD. CVE-2026-73570.
  • Zimbra Security Center.
  • BleepingComputer. Hackers breached over 270 Zimbra servers in ongoing attacks.
  • SecurityWeek. CISA Warns of Exploited Gitea Vulnerability.

This article summarizes publicly available information as of August 2026.

Subscribe for latest updates & insights

Please enable JavaScript in your browser to complete this form.