Analysis
Zimbra, again: unauthenticated command injection over SMTP
CVE-2026-73570 needs no credentials and no user interaction — a crafted SMTP request executes commands as the zimbra user. Mail servers accept connections from strangers by definition, which is what makes pre-auth bugs in them a different category of problem.
CVE-2026-73570T1190T1059.004