
SANS Stormcast Episode Highlights Critical Vulnerabilities and Patch Urgency in SolarWinds, Zimbra, and Apple Systems
The July 22, 2026, episode of the SANS Internet Storm Center Stormcast, hosted by Johannes Ullrich in Jacksonville, Florida, examined how operating systems and browsers detect captive portals on public Wi-Fi networks. Major platforms use specific HTTP-based URLs to identify captive portals, generating traffic that may appear anomalous in network logs due to automatic, user-unaware requests. SolarWinds released an update for its Serv-U product, patching 16 vulnerabilities—15 rated critical (CVSS 9.1)—including an unauthenticated arbitrary code execution flaw (CVE-2026-28304) exploitable remotely as root, with reduced impact on Windows deployments. Zimbra addressed multiple security issues in its webmail software, notably a command injection vulnerability in the SNMP monitoring component (requiring SNMP notifications to be enabled) and several cross-site scripting flaws, some exploitable via email. Apple silently fixed a vulnerability in its Hide My Email system, previously reported by 404 Media, which leaked users’ real email addresses when oversized emails were sent to proxy addresses. The episode highlighted the urgency of applying these patches, particularly for exposed SolarWinds Serv-U instances and Zimbra deployments with SNMP enabled.