Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570
CISA lists this as exploited in the wild. Unpatched Zimbra Collaboration Suite (ZCS) systems are exposed to active attacks now.
Apply the vendor's security update for Zimbra Collaboration Suite (ZCS).
