Zimbra CVE-2026-73570 Harvested the Signing Keys That Authenticate Every Session on the Platform
The Identity Layer Breach Harvested authentication secrets — specifically the zimbraPreAuthKey, zimbraAuthTokenKey, and zimbraTwoFactorAuthSecret — have transformed the exploitation of CVE-2026-73570 from a localized email breach into a permanent, platform-wide identity compromise. By obtaining these keys, attackers can generate valid session tokens and pre-authenticated login URLs for any account, effectively bypassing traditional credential-based security and…