Zimbra command-injection flaw (CVE-2026-73570) exploited before public disclosure
Tags Policy & Law

Attackers exploited a high-severity command-injection flaw in Zimbra Collaboration Suite, CVE-2026-73570, in the weeks after a fix shipped but before the bug was publicly disclosed, according to Microsoft. The vulnerability carries a CVSS score of 8.9 and lets unauthenticated attackers run code remotely on ZCS versions before 10.1.20. Zimbra released the fix on July 20, 2026, public disclosure followed on August 13, and CERT Polska warned of exploitation on August 17. Microsoft observed two distinct out-of-band scanning tools probing the vulnerable injection point between July 28 and August 7.
Technical significance
Exploitation beginning between patch release and public disclosure points to attackers reverse-engineering fixes, a pattern that argues for faster coordinated disclosure. Mail servers remain a high-value target because compromising them yields credentials and message access.