Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: High
Victim: Organizations using Zimbra Collaboration (ZCS)
Incident: Active exploitation of a command injection flaw in Zimbra SNMP notifications.
Impact: Complete system compromise via unauthenticated remote code execution.
Attacker: Unidentified threat actors
Analysis: The vulnerability CVE-2026-73570 allows remote attackers to execute arbitrary operating system commands via specially crafted SMTP requests. This exploit vector requires the optional zimbra-snmp package to be installed and notifications to be enabled. CERT Polska has confirmed that this flaw is currently being exploited in the wild.
Recommendations: Update Zimbra Collaboration to version 10.1.20 or newer immediately.; Audit /var/log/zimbra.log for suspicious and unexpected service restarts.; Scan /tmp/ and Jetty webapps directories for unauthorized files created within the last 30 days.
Source: The Hacker News
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source
Latest Developments
Update — 2026-08-20 19:32 UTC
Active exploitation of a high-severity RCE vulnerability (CVE-2026-73570) in Zimbra. Full system compromise, unauthorized email access, and potential lateral movement across the network. The vulnerability, tracked as CVE-2026-73570, exists within the optional zimbra-snmp package when SNMP notifications are enabled. This flaw allows remote, unauthenticated attackers to execute arbitrary operating system commands with Zimbra user privileges. CERT Polska has confirmed active exploitation, which could lead to full server compromise and lateral movement within the network.
Corroborating source: securityweek.com
Update — 2026-08-25 16:26 UTC
Active exploitation of a remote code execution vulnerability in Zimbra. Full takeover of user communications and potential for internal network mapping. The vulnerability, CVE-2026-73570, allows unauthenticated remote code execution through improper sanitization of SNMP notifications. Because this configuration is often enabled by default, many installations are vulnerable to total system compromise. CISA’s urgent patching deadline underscores the increasing speed at which attackers are weaponizing disclosed flaws.
Corroborating source: darkreading.com
Update — 2026-08-25 17:18 UTC
Widespread exploitation of a remote code execution vulnerability in Zimbra servers. Full server compromise allowing unauthenticated attackers to execute arbitrary code and steal sensitive emails. Attackers are leveraging a command injection flaw in the SNMP monitoring component of the Zimbra Collaboration Suite to achieve remote code execution. The vulnerability, CVE-2026-73570, allows unauthenticated access when SNMP notifications are enabled. Given the wide use of ZCS in government and business sectors, this presents a significant risk of data exfiltration.
Corroborating source: bleepingcomputer.com