Zimbra CVE-2026-73570: Patch the Mail Server, Then Prove It Wasn't Already Owned
Attackers are exploiting a Zimbra SNMP command injection flaw after a fixed version was already available. The real work is not only patching, but compromise triage.
3 articles
Attackers are exploiting a Zimbra SNMP command injection flaw after a fixed version was already available. The real work is not only patching, but compromise triage.
Russian-aligned espionage groups exploited stored XSS flaws in Zimbra, SOGo, Roundcube, MDaemon, and Kerio. Opening a message was enough to lose credentials, email, and persistent access.
BEC caused $3.05 billion in reported US losses in 2025 alone — without a single exploit. Here's the full attack chain from mailbox compromise to wire fraud, and the controls that actually stop it.