Zimbra flaw CVE-2026-73570 exploited in the wild: patch shipped three weeks before disclosure
The unauthenticated command-injection flaw CVE-2026-73570 in ZCS has been exploited since late July to steal email; 274 servers compromised, fix in ZCS 10.1.20.