Back to all news
Security

Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets

The Hacker News·September 30, 2026·1 min read
Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets

Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite to deploy web shells and access mailbox data, according to Microsoft Security Research. The attack exploits CVE-2026-73570, an unauthenticated operating system command injection flaw with a CVSS score of 8.9, which can lead to remote code execution when Simple Network Management Protocol is used.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store