Home / Aug 21, 2026 / Story
0
#7 The Hacker News general August 20, 2026 at 13:24 UTC

Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution

By [email protected] (The Hacker News)

AI Summary

CVE-2026-73570 (CVSS 8.9), a command injection flaw in Zimbra Collaboration Suite enabling unauthenticated remote code execution via the SNMP component, is now under active exploitation according to Poland's CERT Polska. The vulnerability has been patched, but active exploitation makes unpatched Zimbra deployments an immediate priority for remediation. Zimbra servers are a perennial target for nation-state and criminal actors due to their prevalence in government and enterprise email infrastructure.

Relevance score: 82.0/100

# More from August 21