#4
The Hacker News
general
September 30, 2026 at 16:46 UTC
Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets
By [email protected] (The Hacker News)
AI Summary
Microsoft Security Research confirmed active exploitation of CVE-2026-73570 (CVSS 8.9), an unauthenticated OS command injection flaw in Zimbra Collaboration Suite, enabling attackers to deploy web shells and harvest mailbox authentication data via a single crafted email. The attack requires no user interaction beyond delivery, making it particularly dangerous for organizations running internet-exposed Zimbra instances. Patches are available and should be applied immediately.
Relevance score: 87.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →