logo

Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution

ID: a7e5d053-6c88-54c8-8e45-93953a004b63

STIX ID: report--a7e5d053-6c88-54c8-8e45-93953a004b63

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-08-20

Date Updated: 2026-08-20

Author: [email protected] (The Hacker News)

...
...

CERT Polska reports active exploitation of CVE-2026-73570, a Zimbra Collaboration command-injection vulnerability (CVSS 8.9) that can yield unauthenticated remote code execution when zimbra-snmp and SNMP notifications are enabled; Zimbra released a patch in version 10.1.20 and administrators are advised to check zimbra logs and recent files in /opt/zimbra/jetty/webapps/* and /opt/zimbra/jetty_base/webapps/*/tmp/ for signs of compromise. The bulletin also contextualizes the threat by referencing recent Zimbra-targeting campaigns attributed to the Russia-linked Laundry Bear group that weaponized a prior Zimbra vulnerability.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.