Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets
Unauthenticated command injection in Zimbra Collaboration Suite allows remote code execution and mailbox data theft

Key Takeaways
- Threat actors are exploiting CVE-2026-73570, an unauthenticated OS command injection flaw in Zimbra Collaboration Suite, to deploy web shells and harvest mailbox authentication secrets.
- The vulnerability has a CVSS score of 8.9 and is triggered via the SNMP protocol vector.
- Exploitation results in remote code execution, allowing unauthorized access to mailbox data.
Related Security News
CISA Issues Advisory for Four Critical Vulnerabilities in Monta monta.app Charging Station Software
The Cybersecurity and Infrastructure Security Agency (CISA) has published advisory ICSA-26-274-02 disclosing four vulnerabilities in Monta monta.app, a widely used electric vehicle charging station management platform. The flaws span missing authentication, lack of rate limiting on WebSocket endpoints, predictable session identifiers, and insufficiently protected credentials. All versions of the software are affected. While no active exploitation has been confirmed, the CVSS scores range from 7.5 to 9.4, classifying three as Critical and one as High severity. The advisory urges operators to enable OCPP 1.6 Security Profile 2 and apply interim mitigations such as rate limiting.




