search
Zimbra
Trends
- 1Microsoft details Zimbra flaw allowing code execution via email●Zimbra CVE-2026-73570 lets one crafted email run code. Microsoft details the Zimbra command injection attacks: web shell
Microsoft researchers have detailed attacks exploiting a Zimbra command injection vulnerability, CVE-2026-73570, in which a single crafted email is enough to run code on the mail server. The documented attacks involve deploying web shells, gaining root access, and stealing cryptographic keys. Security teams running Zimbra are being urged to patch and review their servers for signs of compromise.
- 2Critical Zimbra flaw CVE-2026-73570 actively exploited●🤖 CVE-2026-73570 (CVSS 8.9): unauthenticated OS command injection in Zimbra Collaboration Suite via its SNMP service, no
A critical vulnerability, CVE-2026-73570 with a CVSS score of 8.9, in Zimbra Collaboration Suite allowed unauthenticated attackers to run operating system commands through its SNMP service. According to Microsoft Security Research, attackers exploited the flaw to deploy web shells and steal mailbox credentials. A patch has been released, and security teams are urged to update affected servers promptly.