VMTech
Discuss a project

Active Exploitation Reported for Zimbra SNMP Command Injection

Active Exploitation Reported for Zimbra SNMP Command Injection

CERT Polska has warned that attackers are actively exploiting CVE-2026-73570, a command-injection vulnerability in Zimbra Collaboration (ZCS) that can lead to unauthenticated remote code execution. The flaw carries a CVSS score of 8.9 and was fixed by Zimbra in version 10.1.20, released last month.

The vulnerability affects ZCS installations before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Under those conditions, an unauthenticated attacker can send specially crafted SMTP requests and potentially execute arbitrary operating-system commands as the Zimbra user.

SNMP notification handling is the attack path

The National Vulnerability Database describes the issue as improper sanitization of untrusted input during SNMP notification processing. That processing weakness creates a command-injection path rather than requiring an attacker to authenticate to the mail platform first.

The configuration prerequisites matter: the vulnerable package must be present and SNMP notifications must be enabled. But CERT Polska's notice that exploitation is already under way makes checking those conditions urgent for organisations operating affected Zimbra servers.

What administrators should examine

CERT Polska advised administrators to inspect /var/log/zimbra.log for suspicious Zimbra service restarts. It also recommended checking for files created within the past 30 days in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/.

  • Verify whether the server is running Zimbra Collaboration 10.1.20 or a later patched release.
  • Determine whether zimbra-snmp is installed and whether SNMP notifications are enabled.
  • Review the specified log and filesystem locations for indicators highlighted by CERT Polska.

Zimbra vulnerabilities have repeatedly drawn threat-actor attention. In a recent roundup of enterprise threat activity, enterprise threat activity roundup shows how vulnerabilities and ClickFix chains continue to create operational pressure; the Zimbra case adds a mail-server issue with an unauthenticated execution route.

Mail infrastructure remains a high-value target

Last month, the U.S. government detailed a phishing campaign attributed to the Russia-linked group Laundry Bear, also tracked as CL-STA-1114, TA488, UNK_PitStop, and Void Blizzard. The campaign targeted Zimbra mail servers at Western government and commercial organisations from at least July 2025.

That activity exploited CVE-2025-66376, a stored cross-site scripting flaw in Zimbra's Classic UI, to deliver the ZimReaper JavaScript payload and collect email communications and other sensitive data. It is distinct from CVE-2026-73570, but it illustrates the sustained focus on Zimbra environments.

The practical business implication is to treat patch verification, optional-component review, and targeted log and filesystem checks as immediate operational tasks for every exposed Zimbra deployment.

#zimbra#cybersecurity#vulnerability#emailsecurity
Open analytics
On the site 1 views
min read 3 20.08.2026
Instagram

Active Exploitation Reported for Zimbra SNMP Command Injection

Open the post on Instagram ↗