AI Stories on SHORT INFO are generated & curated with AI
2 linked sources 21 Aug, 12:11

A critical Zimbra email server flaw is now under active exploitation

Poland's CERT Polska says attackers are actively exploiting CVE-2026-73570, an unauthenticated command injection flaw in Zimbra Collaboration Suite's SNMP component, letting them run system commands as the Zimbra user. Patched last month, but over 12,100 servers remain exposed online.

CERT Polska warned this week that attackers are actively exploiting CVE-2026-73570 (CVSS 8.9), a command injection flaw in Zimbra Collaboration Suite's SNMP monitoring component that lets an unauthenticated attacker execute arbitrary OS commands as the Zimbra user. The flaw affects servers running the optional zimbra-snmp package with SNMP notifications enabled. Zimbra patched it last month in version 10.1.20 (released July 20, 2026), but Shadowserver still counts more than 12,100 exposed Zimbra servers online, most in Europe and Asia, with no way to tell how many are already patched. CERT Polska is telling admins to check zimbra.log for unexpected service restarts and new files in the Zimbra web app directories. Sources: Bleeping Computer, The Hacker News.

#cyber
Published on