Zimbra Flaw Is Being Exploited in the Wild

CERT Polska says attackers are actively exploiting CVE-2026-73570 in Zimbra Collaboration Suite, and Zimbra shipped version 10.1.20 on July 20 to fix it. The flaw sits in SNMP notification handling, a feature often enabled for monitoring, so a server that looks like ordinary mail infrastructure can already expose the vulnerable path. An unauthenticated attacker can send a specially crafted SMTP request that slips through unsafe input handling in the SNMP notification code and makes the server run operating-system commands as the Zimbra user. In plain terms, the mail server itself becomes the entry point, and SNMP settings that were meant for alerts widen the attack surface instead of staying passive. For organizations that run internet-facing Zimbra, especially in government and other regulated environments, the exposure is not theoretical: a monitoring feature can now be the route into the mail host. What remains after patching is the trust question around any deployment that left SNMP notifications enabled while the service was reachable from the internet.

Part of the PlainSec briefing for 2026-08-20

Every edition of this story: Zimbra Flaw Is Being Exploited in the Wild

Sources