Zimbra CVE -2026-73570: Identity layer vulnerabilities lead to severe damage to platform security
2026-10-04 13:37:59
According to CoinMeta, a vulnerability with the ID Zimbra CVE-2026-73570 has caused severe breaches in identity layer security. Attackers, by obtaining signature keys, are able to generate valid session tokens and perform pre-authenticated logins to URL, bypassing traditional authentication measures and allowing them to continuously access the entire Zimbra environment. This vulnerability has a CVSS score of 8.9 and is classified as an unauthenticated operating system command injection flaw, affecting all versions prior to 10.1.20. It is recommended to update to version 10.1.20 or later immediately. If immediate patching is not possible, users should uninstall the zimbra-snmp package, disable SNMP notifications, and restrict access to SNMP and SMTP.
Bullish 0
Bearish 0
Source:Forkast
This content is for market information only and does not constitute investment advice.