chiprook
← Security
SecurityOctober 1, 2026, 19:55

Zimbra CVE-2026-73570 Exploited in the Wild Before Public Disclosure

Microsoft reports that attackers exploited a high-severity OS command injection flaw in Zimbra Collaboration Suite (CVE-2026-73570, CVSS 8.9) between the July 20 patch release and the August 13 public disclosure. The bug allows unauthenticated remote code execution as the Zimbra user, enabling JSP webshells and privilege escalation to root.

Zimbra CVE-2026-73570 Exploited in the Wild Before Public Disclosure
#Zimbra#Microsoft
Read next
Security

WordPress CVE-2026-87902 Exploited Within Hours of Disclosure

Security

Roundcube SQL injection CVE-2026-48842 exploited in the wild

Security

CVE-2026-75650: critical RCE in Adobe Commerce and Magento exploited in the wild

Security

Public PoC Released for Apple CoreGraphics CVE-2026-86950