#7
The Hacker News
general
August 20, 2026 at 13:24 UTC
Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution
By [email protected] (The Hacker News)
AI Summary
CVE-2026-73570 (CVSS 8.9), a command injection flaw in Zimbra Collaboration Suite enabling unauthenticated remote code execution via the SNMP component, is now under active exploitation according to Poland's CERT Polska. The vulnerability has been patched, but active exploitation makes unpatched Zimbra deployments an immediate priority for remediation. Zimbra servers are a perennial target for nation-state and criminal actors due to their prevalence in government and enterprise email infrastructure.
Relevance score: 82.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →