Critical Zimbra flaw actively exploited to steal emails
Microsoft warned that a critical vulnerability in Zimbra Collaboration Suite is being actively exploited by attackers to steal email backups and authentication credentials. Tracked as CVE-2026-73570, the flaw allows remote OS command execution without authentication. The Shadowserver Foundation found at least 274 Zimbra instances compromised.