Microsoft catches hackers exploiting Zimbra bug before disclosure
Attackers exploited CVE-2026-73570, an unauthenticated Zimbra Collaboration Suite command injection flaw, before it was publicly disclosed—sending crafted email to exposed servers to run commands and then using web shells/reverse shells to escalate privileges and reach root access on at least one system.
Oct 1, 2026 ·
The Register
















