Actively Exploited Zimbra Flaw Lets Unauthenticated Attackers Execute Shell Commands
ID: 0e1ce286-0671-5249-8592-94f1455dc6f8
STIX ID: report--0e1ce286-0671-5249-8592-94f1455dc6f8
Feed Name: Cyber Press
Active exploitation has been disclosed for a critical Zimbra command-injection vulnerability (CVE-2026-73570) affecting instances with snmp_notify enabled and the swatchdog service running (enabled by default). The flaw allows unauthenticated remote attackers to execute shell commands as the zimbra user, enabling web shells, data access, persistence, and potential privilege escalation; Cert Polska confirms active campaigns and urges immediate upgrade to Zimbra 10.1.20 and inspection of zimbra logs, webapp directories, and /tmp for indicators of compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
