Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets
Attackers are exploiting a patched command-injection flaw in Zimbra Collaboration Suite to install web shells and access mailbox data. Microsoft identifies CVE-2026-73570 as an unauthenticated operating-system command injection vulnerability with a CVSS score of 8.9 that can enable remote code execution through SNMP.
Active exploitation of an unauthenticated flaw that can lead to remote code execution poses a serious risk to organizations running Zimbra Collaboration Suite, even though a patch is available.