โ† Back to Feed

Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution

CVE-2026-73570

August 20, 2026 ยท The Hacker News ยท Severity: HIGH

A patched security flaw in Zimbra Collaboration (ZCS) is being actively exploited in the wild, according to CERT Polska. The vulnerability allows unauthenticated remote code execution when the optional zimbra-snmp package is installed and SNMP notifications are enabled. The flaw affects Zimbra Collaboration versions before 10.1.20. Organizations running Zimbra with the SNMP package enabled are urged to update immediately to prevent compromise. ๐Ÿ“Œ **Analyst Note:** The active exploitation of this Zimbra SNMP flaw underscores the risk of optional components that expand the attack surface. Organizations using Zimbra should verify whether the SNMP package is installed and disable it if not needed. Prompt patching is critical as unauthenticated RCE vulnerabilities in email collaboration platforms are frequently targeted by threat actors.

A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency Response Team (CERT Polska). The vulnerability in question is CVE-2026-73570 (CVSS score: 8.9), which refers to a case of command injection that can lead to remote code execution. "A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed, and SNMP notifications are enabled," according to a description of the flaw in the NIST National Vulnerability Database (NVD). "Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user." The security issue was patched by Zimbra last month with the release of version 10.1.20. In a bulletin issued earlier this week, CERT Polska alerted of active exploitation efforts targeting the flaw, urging users to check the "/var/log/zimbra.log" file for suspicious Zimbra service restarts, as well as for files created in the below directories within the last 30 days - /opt/zimbra/jetty/webapps/ /opt/zimbra/jetty_base/webapps/ /tmp/ Vulnerabilities in Zimbra have been frequently targeted by threat actors. Last month, the U.S. government disclosed details of a phishing campaign orchestrated by a Russia-linked adversary called Laundry Bear (aka CL-STA-1114, TA488, UNK_PitStop, and Void Blizzard) that involved targeting Zimbra mail servers belonging to Western government and commercial organizations since at least July 2025. The campaign was found to have weaponized CVE-2025-66376, a stored cross-site scripting vulnerability in Zimbra's Classic UI, to deliver a malicious JavaScript payload dubbed ZimReaper to harvest email communications and other sensitive data. Found this article interesting? Follow us on Google News , Twitter and LinkedIn to read more exclusive content we post.

Key Takeaways

  • A Zimbra Collaboration SNMP flaw is being actively exploited for unauthenticated remote code execution.
  • The vulnerability affects Zimbra Collaboration versions before 10.1.20 with the optional zimbra-snmp package installed.
  • CERT Polska reported the active exploitation, urging organizations to patch immediately.
  • Organizations should disable the zimbra-snmp package if not required to reduce attack surface.
โ˜• Buy a Coffee