Over 270 Zimbra Collaboration Suite servers have been breached through exploitation of a critical remote code execution vulnerability, exposing organizations to significant security risks.
CISA added CVE-2026-73570, an OS command injection vulnerability in Zimbra Collaboration Suite, to its Known Exploited Vulnerabilities Catalog after active exploitation was observed.
CISA warns that Russian state-sponsored group Laundry Bear is exploiting a patched Zimbra zero-click vulnerability combined with phishing to steal emails from enterprise Zimbra Collaboration servers.