chiprook
← Security
SecuritySeptember 30, 2026, 22:48

Microsoft warns of Zimbra zero-day exploit targeting mail servers

A zero-day in Zimbra allows unauthenticated command injection via the SNMP notification path, letting attackers steal session tokens and install persistent webshells on mail servers. Microsoft warned that the flaw is being actively exploited.

Microsoft warns of Zimbra zero-day exploit targeting mail servers
#Zimbra#Microsoft
Read next
Security

Apple: zero-day CVE-2026-86950 exploited in targeted attacks

Security

Volexity spots China-aligned UTA0565 exploiting Chrome and Windows zero-days

Security

Two Unpatched Citrix NetScaler RCE Zero-Days Actively Exploited

Security

F5 patches exploited BIG-IP APM zero-day enabling RCE