Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution
ID: a7e5d053-6c88-54c8-8e45-93953a004b63
STIX ID: report--a7e5d053-6c88-54c8-8e45-93953a004b63
Feed Name: The Hacker News
CERT Polska reports active exploitation of CVE-2026-73570, a Zimbra Collaboration command-injection vulnerability (CVSS 8.9) that can yield unauthenticated remote code execution when zimbra-snmp and SNMP notifications are enabled; Zimbra released a patch in version 10.1.20 and administrators are advised to check zimbra logs and recent files in /opt/zimbra/jetty/webapps/* and /opt/zimbra/jetty_base/webapps/*/tmp/ for signs of compromise. The bulletin also contextualizes the threat by referencing recent Zimbra-targeting campaigns attributed to the Russia-linked Laundry Bear group that weaponized a prior Zimbra vulnerability.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
