Threat Brief — 2026-08-25 — KEV deadline passes, gamers in crosshairs
The CISA Known Exploited Vulnerabilities remediation deadline for the actively exploited Zimbra Collaboration Suite RCE expired yesterday (2026-08-24), meaning any federal or follower-organisation still running unpatched ZCS is now out of compliance and exposed to in-the-wild exploitation. A new malware-distribution campaign is also worth attention: "Weedhack" is being pushed to gamers through fake Minecraft clients and SEO poisoning, with McAfee Labs already blocking 6,300+ attempts.
Top items
- Zimbra RCE — CISA KEV deadline expired, active exploitation continues. CVE-2026-73570KEV (CVSS 8.9) is an OS command injection in Zimbra Collaboration Suite's SNMP monitoring component (affects ZCS before 10.1.20 when SNMP notifications are enabled). CISA added it to KEV on 2026-08-21 with a 3-day deadline of 2026-08-24 — now lapsed. The vulnerability is known-exploited in the wild. First reported 2026-08-20 by BleepingComputer. (src: BleepingComputer / CISA)
- Weedhack malware spread via fake Minecraft clients and SEO poisoning. McAfee Labs detected and blocked over 6,300 attempts to deliver the Weedhack malware family through websites masquerading as legitimate Minecraft clients, supplemented by SEO poisoning to redirect gamers to malicious downloads. No specific CVE or KEV linkage; primary target is the gaming community. (src: The Hacker News)
Themes
KEV clock ticking. Two KEV-catalogued vulnerabilities from this week — Zimbra (deadline 2026-08-24, now passed) and Oracle HTTP Server/WebLogic Proxy Plug-in (deadline 2026-08-27) — create a narrow patching window. The Zimbra deadline has already lapsed while active exploitation continues, putting laggard organisations at immediate risk.
Social-engineering of non-enterprise users. The Weedhack campaign continues a pattern seen across recent Threat briefs: threat actors bypass enterprise defences by targeting end users through trusted leisure channels (gaming mods, fake app updates, SEO poisoning) rather than traditional phishing.
===
