Microsoft warns of Zimbra zero-day exploit targeting mail servers
A zero-day in Zimbra allows unauthenticated command injection via the SNMP notification path, letting attackers steal session tokens and install persistent webshells on mail servers. Microsoft warned that the flaw is being actively exploited.
- Flaw is unauthenticated command injection in SNMP notifications
- Attackers steal session tokens and deploy webshells
- Exploitation is active, Microsoft warns
Read next
Security