Posts tagged with “zimbra”

Zimbra CVE-2026-73570 exploited before public disclosure

Attackers began abusing a high-severity command injection flaw in Zimbra Collaboration Suite (ZCS) in the weeks after a fix was released but before the bug was publicly disclosed, according to Microsoft.

The vulnerability, tracked as CVE-2026-73570, carries a CVSS score of 8.9. It affects ZCS versions before 10.1.20 and allows unauthenticated attackers to run code remotely on vulnerable mail servers.

How the flaw works

The problem lies in how ZCS handles SNMP notifications. SNMP (Simple Network Management Protocol) is commonly used to monitor and manage network devices and services. In affected versions, untrusted input processed during these notifications is not properly sanitized, which opens the door to OS command injection.

Read More