logo

Actively Exploited Zimbra Flaw Lets Unauthenticated Attackers Execute Shell Commands

ID: 0e1ce286-0671-5249-8592-94f1455dc6f8

STIX ID: report--0e1ce286-0671-5249-8592-94f1455dc6f8

Feed Name: Cyber Press

Threat Score
85/100

Date Published: 2026-08-24

Date Updated: 2026-08-24

Author: Tamilselvan

...
...

Active exploitation has been disclosed for a critical Zimbra command-injection vulnerability (CVE-2026-73570) affecting instances with snmp_notify enabled and the swatchdog service running (enabled by default). The flaw allows unauthenticated remote attackers to execute shell commands as the zimbra user, enabling web shells, data access, persistence, and potential privilege escalation; Cert Polska confirms active campaigns and urges immediate upgrade to Zimbra 10.1.20 and inspection of zimbra logs, webapp directories, and /tmp for indicators of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.