Skip to main content
CyberReportedHighDevelopingFeatured
7.1

Zimbra zero-day CVE-2026-73570 exploited in the wild before patch

A zero-day vulnerability in Zimbra Collaboration Suite, CVE-2026-73570, is being actively exploited via specially crafted emails without user interaction, prior to public disclosure. The attack vector suggests targeted espionage or ransomware campaigns against email infrastructure. The lack of a patch and active exploitation elevates risk for organizations using Zimbra.

SecurityWeek1 day agoengCredibility 25%View source

Score Breakdown

Mosaic Score7.1
Model confidence0.7
Significance0.8
Source credibility0.3
Source

Related signals

8 found