VMTech
Discuss a project →

Active Exploitation Reported for Zimbra SNMP Command Injection

Active Exploitation Reported for Zimbra SNMP Command Injection

CERT Polska has warned that attackers are actively exploiting CVE-2026-73570, a command-injection vulnerability in Zimbra Collaboration (ZCS) that can lead to unauthenticated remote code execution. The flaw carries a CVSS score of 8.9 and was fixed by Zimbra in version 10.1.20, released last month.

The vulnerability affects ZCS installations before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Under those conditions, an unauthenticated attacker can send specially crafted SMTP requests and potentially execute arbitrary operating-system commands as the Zimbra user.

SNMP notification handling is the attack path

The National Vulnerability Database describes the issue as improper sanitization of untrusted input during SNMP notification processing. That processing weakness creates a command-injection path rather than requiring an attacker to authenticate to the mail platform first.

The configuration prerequisites matter: the vulnerable package must be present and SNMP notifications must be enabled. But CERT Polska's notice that exploitation is already under way makes checking those conditions urgent for organisations operating affected Zimbra servers.

What administrators should examine

CERT Polska advised administrators to inspect /var/log/zimbra.log for suspicious Zimbra service restarts. It also recommended checking for files created within the past 30 days in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/.

  • Verify whether the server is running Zimbra Collaboration 10.1.20 or a later patched release.
  • Determine whether zimbra-snmp is installed and whether SNMP notifications are enabled.
  • Review the specified log and filesystem locations for indicators highlighted by CERT Polska.

Zimbra vulnerabilities have repeatedly drawn threat-actor attention. In a recent roundup of enterprise threat activity, enterprise threat activity roundup shows how vulnerabilities and ClickFix chains continue to create operational pressure; the Zimbra case adds a mail-server issue with an unauthenticated execution route.

Mail infrastructure remains a high-value target

Last month, the U.S. government detailed a phishing campaign attributed to the Russia-linked group Laundry Bear, also tracked as CL-STA-1114, TA488, UNK_PitStop, and Void Blizzard. The campaign targeted Zimbra mail servers at Western government and commercial organisations from at least July 2025.

That activity exploited CVE-2025-66376, a stored cross-site scripting flaw in Zimbra's Classic UI, to deliver the ZimReaper JavaScript payload and collect email communications and other sensitive data. It is distinct from CVE-2026-73570, but it illustrates the sustained focus on Zimbra environments.

The practical business implication is to treat patch verification, optional-component review, and targeted log and filesystem checks as immediate operational tasks for every exposed Zimbra deployment.

#zimbra#cybersecurity#vulnerability#emailsecurity

CVE-2026-73570 response checklist for Zimbra administrators

The immediate task is to establish whether a Zimbra server meets the conditions described for CVE-2026-73570, then check for possible signs of exploitation rather than relying on version information alone.

Confirm whether the server is exposed

The reported command-injection path applies to Zimbra Collaboration installations before version 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Check all three conditions when assessing exposure.

  • Verify that Zimbra Collaboration is running version 10.1.20 or later.
  • Determine whether the optional zimbra-snmp package is installed.
  • Confirm whether SNMP notifications are enabled.

Review the reported indicators

Because active exploitation has been reported, administrators should examine the locations identified in the notice even after confirming the current software version.

  • Inspect /var/log/zimbra.log for suspicious Zimbra service restarts.
  • Review recently created files in /opt/zimbra/jetty/webapps/.
  • Check /opt/zimbra/jetty_base/webapps/ and /tmp/ for recent files.
  • Use the stated 30-day review period when checking file creation activity.

Keep this issue separate from other Zimbra flaws

CVE-2026-73570 is an unauthenticated command-injection issue associated with SNMP notification processing. It is distinct from CVE-2025-66376, the stored cross-site scripting flaw discussed in the earlier phishing campaign.

  • Track findings under the correct CVE to avoid mixing investigation paths.
  • Base the assessment on version, package and notification settings.

Frequently asked questions

What is CVE-2026-73570?

It is a Zimbra Collaboration command-injection vulnerability in SNMP notification processing that can permit unauthenticated remote code execution under the described configuration conditions.

Does CVE-2026-73570 affect every Zimbra installation?

No. The supplied advisory details point to releases before 10.1.20 where zimbra-snmp is installed and SNMP notifications are enabled.

Which locations should administrators inspect?

Review /var/log/zimbra.log for suspicious service restarts and check /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/ and /tmp/ for recently created files.

Open analytics
On the site 176 views
min read 3 20.08.2026
On Instagram 2 views
On Instagram 1 reach
Instagram

Active Exploitation Reported for Zimbra SNMP Command Injection

Open the post on Instagram ↗