Zimbra Exploits, Quantum Certificates, and RSA Panic

Homelab Highlights for 2026-09-30: self-hosting and homelab notes worth knowing.

[Audio embed placeholder]

News Roundup

Attackers have been exploiting critical Zimbra flaw to steal emails

Attackers are exploiting a critical vulnerability (CVE-2026-73570) in Zimbra Collaboration Suite that allows unauthenticated remote command injection. The goal is to steal email backups and authentication credentials.

Why it matters: If you run a Zimbra server, applying the patch from July 20th is critical. The attackers are actively targeting unpatched instances to harvest sensitive data.

Source: Ars Technica

OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted

OpenSSL patched a high-severity flaw in DTLS, the TLS variant for UDP traffic. The bug can cause heap memory to leak to the other side of a connection or crash the program during handshake retransmissions.

Why it matters: Services using DTLS (like some VPNs or QUIC) should update OpenSSL. While not as widespread as the Zimbra issue, it’s a security update worth including in your next maintenance cycle.

Source: The Hacker News

Cloudflare plans to issue quantum-safe TLS certificates

Cloudflare announced it will begin issuing free, hybrid TLS certificates that combine classic cryptography with post-quantum algorithms, as part of a multi-year overhaul of web authentication infrastructure.

Why it matters: This marks a concrete, early step in the transition to post-quantum cryptography. For homelabbers, it’s a development to watch as the ecosystem evolves over the coming years.

Source: Ars Technica

Plex Web v4.162.1 Released

Plex Web version 4.162.1 adds new audio playback settings for loudness normalization and dialog boost, and fixes issues with remote access detection and IPv6 handling.

Why it matters: A straightforward update for Plex media server operators, offering quality-of-life audio improvements and networking fixes.

Source: r/PleX

Tool & Software Highlight: There’s a new way to break RSA that’s faster than anything we’ve seen before

A headline about a new, faster method to break RSA encryption sparked concern in the self-hosted community. The attack, however, only works against a specific, rarely used implementation called ‘blind-signature’ or ‘textbook’ RSA, not the PKCS or PSS-padded RSA used in standard TLS certificates.

Why it matters: For homelab operators, standard TLS certificates remain secure. This is a useful reminder to understand cryptographic terms, but it’s not a call for immediate action on your reverse proxy or web server configurations.

Source: r/selfhosted

Sources

Transcript

Host A: Welcome to Homelab Highlights, the show that surfaces practical homelab wins and useful self-hosted tools.

Host A: A headline about a new, faster way to break RSA made the rounds today, and it sparked the usual kind of panic in the self-hosted community. The Ars Technica article details a new attack that’s faster than anything seen before, but here’s the key: it only works against blind-signature RSA, which is a specific cryptographic protocol used in things like Privacy Pass. That’s not the same as the RSA in your TLS certificates.

Host B: Right. The overwhelming majority of RSA in use today—including the TLS certificates most of us deal with—uses PKCS or PSS padding, which adds data to the plaintext before encryption. That’s what prevents this kind of attack. [conversational] So for a homelab operator, the takeaway is straightforward: standard TLS certificates are fine. This is not a call to rip and replace everything. The academic work is solid, but the practical threat surface for anyone running standard TLS is essentially zero.

Host A: It’s a good reminder to understand what textbook RSA even means, but it’s not a five-alarm fire for your reverse proxy.

Host A: Moving to active threats, attackers have been exploiting a critical flaw in Zimbra Collaboration Suite to steal emails. Microsoft warned about this vulnerability, tracked as CVE-2026-73570, which lets attackers remotely issue operating system commands without any authentication. Zimbra’s maintainer issued a patch on July 20th, but didn’t disclose the vulnerability for over three weeks after that. The Shadowserver Foundation found 274 compromised instances, and they’re currently tracking about 10,000 instances still on the internet. [with emphasis] For anyone running a Zimbra server, that patch from July is an absolute must-apply if it hasn’t been done yet. The attackers were specifically after email data and authentication credentials, so this is a very targeted campaign. If you’re running Zimbra in a homelab or small business environment, this one deserves immediate attention.

Host B: In a quicker note, OpenSSL fixed a high-severity DTLS flaw. DTLS is the TLS variant for UDP traffic—think WireGuard, VPNs, or QUIC. The flaw can leak heap memory to the other side of a connection or crash the program. It happens when DTLS resends a handshake message on timeout. The fix is out, so a standard OpenSSL update covers it. If you’re running any services that depend on DTLS, make sure your OpenSSL is up to date. It’s not as immediately critical as Zimbra, but it’s worth rolling into your next patch cycle.

Host A: Looking further ahead, Cloudflare announced plans to issue quantum-safe TLS certificates. They’re using an open source platform to issue hybrid certificates that combine classic TLS with a post-quantum equivalent. They’ll be free, and Cloudflare is acquiring a trusted root from GlobalSign to help establish ubiquity across the ecosystem. [thoughtful] The article makes it clear this is a years-long project, but it’s a concrete step toward the post-quantum cryptographic transition that’s been on the horizon. They’re starting with a limited preview and targeting a hybrid approach so sites can support both classic and quantum-safe clients during a long transition. For homelab operators, this is more of a watch-and-wait situation, but it’s good to see the infrastructure starting to move.

Host B: A quick update for the media server crowd: Plex Web v4.162.1 is out with new audio playback settings like Normalize Loudness and Boost Dialog, plus fixes for remote access detection and IPv6 handling. If you’re running Plex in a homelab, it’s a straightforward update with some quality-of-life improvements.

Host B: For our tool highlight, a community member reported an interesting quirk with the Copyparty WebDAV server. When opening files from a Copyparty network drive on macOS—specifically in the Preview app—the file’s ‘date modified’ timestamp changes even when no edits are made. [curious] The discussion in the thread points to the underlying filesystem as a potential culprit. The user was running exFAT, and similar behavior has been noted on NTFS and other filesystems. It’s one of those minor but annoying quirks that can throw off backup scripts or file organization if you’re not aware of it.

Host A: The thread suggests it might be a macOS Preview behavior rather than a Copyparty issue, but the real takeaway is that different operating systems interact with network shares in unexpected ways. If you’re using Copyparty with macOS clients, this is worth keeping in mind when setting up your backup strategies or relying on file timestamps for anything critical. One commenter suggested testing with cat on the command line to see if the timestamp changes without Preview involved, which is a solid troubleshooting step. It’s a good reminder that WebDAV servers are a bridge between different systems, and those bridges sometimes have quirks worth understanding.

Host A: Our community highlight is a masterclass in homelab scope creep. A user simply wanted more RAM for their ThinkCentre NAS. That thought led them down the rabbit hole of cheap, old enterprise Xeons and Chinese X99 motherboards. What started as a RAM upgrade spiraled into building a 22-core, 128 GB ECC NAS for themselves and a separate Xeon desktop for their spouse. They detail hunting for deals on AliExpress for the motherboard and CPU combo, which is a whole adventure in itself with potential pitfalls. The user ended up with a pair of Xeon E5-2696 v4 processors—basically the budget kings of core count if you’re willing to hunt on the secondhand market.

Host B: [lighter] The best part is the accounting. By selling old gear like a Mac Mini and two ThinkCentres, and navigating AliExpress partial refunds, they calculated the net cost for both complete systems ended up around ninety-two dollars. The author is the first to admit a 22-core Xeon is absolutely not necessary for a home NAS, but the journey through used hardware markets, the build process, and ending up with a massively overbuilt TrueNAS SCALE server for practically nothing? That’s the homelab spirit in a nutshell. They even documented the whole thing with photos and part numbers, so if you’re curious about the X99 route, there’s a solid reference thread. It’s a reminder that sometimes the best homelab deals come from being willing to go down a rabbit hole.

Host A: That’s Homelab Highlights for Wednesday. Until next time, happy hosting!