Skip to content
cve — cve-2026-73570

grep -rl "CVE-2026-73570" ./articles

CVE-2026-73570

Microsoft published its tracking of CVE-2026-73570 on 30 September: a crafted message reaches Zimbra's SNMP notification path and runs commands as the zimbra account, with no authentication and nobody clicking anything. The fix shipped in July. What the intruders take includes the preauth and auth-token keys, which a patch does not invalidate.

1 article — 2026-10-01

Authoritative record

Root Notes reports on this identifier; it does not maintain it. For the vendor advisory, the affected versions and the scoring, NVD and MITRE hold the primary records.

Our coverage

../cve — every identifier we have covered