The Zimbra flaw arrives as an email, and what it takes is the pair of keys that make passwords beside the point
2026-10-01Security
Microsoft published its tracking of CVE-2026-73570 on 30 September: a crafted message reaches Zimbra's SNMP notification path and runs commands as the zimbra account, with no authentication and nobody clicking anything. The fix shipped in July. What the intruders take includes the preauth and auth-token keys, which a patch does not invalidate.