Zimbra CVE-2026-73570 Exploited in the Wild Before Public Disclosure
Microsoft reports that attackers exploited a high-severity OS command injection flaw in Zimbra Collaboration Suite (CVE-2026-73570, CVSS 8.9) between the July 20 patch release and the August 13 public disclosure. The bug allows unauthenticated remote code execution as the Zimbra user, enabling JSP webshells and privilege escalation to root.
- CVE-2026-73570 (CVSS 8.9) affects ZCS before 10.1.20 via SNMP notification processing
- Patch released July 20, disclosure August 13, exploitation began July 28
- Attackers deployed JSP webshells and escalated privileges to root
- Persistence was established via a systemd service named zimlog.service
Read next
Security