Critical Zimbra RCE Flaw CVE-2026-73570 Actively Exploited via SMTP Injection
A critical unauthenticated remote code execution vulnerability, tracked as CVE-2026-73570, has been identified in Zimbra Collaboration Suite and confirmed actively exploited in the wild. Attackers can send a specially crafted SMTP request to vulnerable Zimbra servers that have the zimbra-snmp package installed and SNMP notifications enabled, triggering arbitrary OS command execution as the zimbra user. CERT Polska published an advisory on August 17, 2026, warning that no user interaction is required and compromise can occur silently while email functions appear normal. Successful exploitation can allow attackers to deploy web shells, access emails and credentials, and establish a foothold within internal networks. Administrators are urged to upgrade to ZCS 10.1.20 or later, disable SNMP notifications immediately, and monitor Zimbra logs for unusual service status entries or unexpected file creation.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in