Hackers Target Zimbra Servers in Active Exploitation Campaign
Reported exploitedZimbra Collaboration SuiteOur summary
CERT Polska has confirmed that attackers are actively exploiting a high-severity vulnerability in Zimbra Collaboration Suite, identified as CVE-2026-73570. The flaw allows unauthenticated attackers to execute arbitrary OS commands when the optional zimbra-snmp package is installed and SNMP notifications are enabled. This critical risk was addressed in version 10.1.20, released on July 20, so administrators should apply the patch immediately to prevent full server compromise, credential harvesting, and lateral movement.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.