Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets
Attackers are exploiting a patched command-injection flaw in Zimbra Collaboration Suite to install web shells and access mailbox data. Microsoft identifies CVE-2026-73570 as an unauthenticated operating-system command injection vulnerability with a CVSS score of 8.9 that can enable remote code execution through SNMP.

