logo

Zimbra Collaboration Suite Flaw Actively Exploited to Execute Arbitrary Commands

ID: 3cdd9b36-5414-56c4-8362-311bb963a89a

STIX ID: report--3cdd9b36-5414-56c4-8362-311bb963a89a

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-08-24

Date Updated: 2026-08-24

Author: Divya

...
...

CERT Polska warns of active exploitation of CVE-2026-73570 — an unauthenticated OS command injection in Zimbra Collaboration Suite (affecting environments with snmp_notify enabled and swatchdog running) that permits execution of shell commands as the zimbra user; organizations are urged to upgrade to Zimbra 10.1.20, inspect /var/log/zimbra.log for suspicious service changes, hunt for unexpected files in Jetty and /tmp, isolate compromised hosts, preserve evidence, and rotate credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.