CVE Tools
Back to feed
Exploited in the wild Zimbra Collaboration Suite rce Zimbra

Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution

The Hacker News·By The Hacker News··1 min read
CVE Tools coverage

CERT Polska has confirmed active in-the-wild exploitation of CVE-2026-73570, a high-severity command injection vulnerability in Zimbra Collaboration Suite versions prior to 10.1.20. The flaw affects installations where the zimbra-snmp package is present and allows unauthenticated attackers to execute arbitrary OS commands by sending crafted SMTP requests that bypass input sanitization during SNMP notification handling. While Zimbra released a patch for this issue in July, the recent confirmation of real-world attacks underscores the urgent need for organizations to verify they have upgraded to version 10.1.20 and should inspect system logs for signs of compromise.