CERT Polska confirmed active exploitation of a critical Zimbra Collaboration Suite remote code execution flaw this week, giving attackers mail-server access without credentials. The same week, Citrix shipped fixes for two NetScaler ADC and Gateway flaws, one a critical authentication bypass that lets an attacker skip the login prompt entirely. Two vendors, two authentication layers, both breached from the front door rather than picked open.
The pattern connects to CISA's parallel warning this week: 361 networks breached in five days, with a new three-day patch window mandated for enterprise flaws under active exploitation. Zimbra and NetScaler sit exactly in that category, internet-facing, authentication-adjacent, and now both under public advisories with working exploit code in circulation. The control that would have changed the outcome is the one CISA just wrote a deadline around: patch within three days of an advisory naming a flaw as actively exploited, not on the next scheduled maintenance window.