An active exploitation of CVE-2026-73570, a high-severity unauthenticated OS command-injection vulnerability in Zimbra Collaboration Suite. Attackers used to obtain root access, establish persistent control, and collect mailbox authentication secrets. The issue resides in Zimbra’s SNMP notification processing path. An attacker can send a specially crafted SMTP request containing shell metacharacters, allowing attacker-controlled input to reach […]
Read the original article:
