
**IceWarp Servers** are under attack via a directory traversal vulnerability, exploited without authentication. A CVSS 7.5 rated vulnerability, assigned CVE-2026-2493, allows remote attackers to disclose sensitive information, potentially attributed to FANCY BEAR.
Post summary
IceWarp servers are being actively exploited via a directory traversal vulnerability (CVE-2026-2493) that allows remote disclosure of sensitive data; no patch or PoC is mentioned.


