< Back to all clusters
[TECHNOLOGY] · United States · 3 sources

started · updated

Zimbra Collaboration Suite vulnerability actively exploited

Threat actors are actively exploiting a critical OS command-injection vulnerability, identified as CVE-2026-73570, within the Zimbra Collaboration Suite (ZCS). The flaw allows remote, unauthenticated attackers to execute arbitrary shell commands as the zimbra user.

The vulnerability specifically affects installations where the SNMP trap service is enabled via the snmp_notify parameter and the swatchdog service is running. Because swatchdog is enabled by default, exposed servers with SNMP notifications configured face a high risk of compromise. Successful exploitation can allow attackers to deploy web shells, steal email data, establish persistence, or use the server to target other systems within an organization.

CISA has urged authorities to patch affected systems within three days, noting that the issue is already being exploited in the wild. Zimbra has released a fix in version 10.1.20. Security experts recommend that administrators verify their current version and upgrade immediately. If immediate updates are not possible, organizations should review whether SNMP trap functionality is necessary and disable the snmp_notify configuration.

Entities

CERT Polska · CISA · Zimbra Collaboration Suite