Home / Oct 01, 2026 / Story
0
#4 The Hacker News general September 30, 2026 at 16:46 UTC

Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets

By [email protected] (The Hacker News)

AI Summary

Microsoft Security Research confirmed active exploitation of CVE-2026-73570 (CVSS 8.9), an unauthenticated OS command injection flaw in Zimbra Collaboration Suite, enabling attackers to deploy web shells and harvest mailbox authentication data via a single crafted email. The attack requires no user interaction beyond delivery, making it particularly dangerous for organizations running internet-exposed Zimbra instances. Patches are available and should be applied immediately.

Relevance score: 87.0/100

# More from October 01