Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [TECHNOLOGY]
2 clusters · 5 sources · 4 days · First seen · Last updated
Zimbra Collaboration Suite security vulnerability
Overview
A critical security vulnerability in the Zimbra Collaboration Suite, identified as CVE-2026-73570, has been identified as a significant threat. The flaw allows unauthenticated attackers to execute operating system commands by sending crafted SMTP requests to servers with SNMP notifications enabled.
Initial reports indicated the vulnerability was being actively exploited. Subsequent details clarified that the risk is particularly high because the swatchdog service is enabled by default on many installations. Successful exploitation can allow attackers to deploy web shells, steal email data, or establish persistence within an organization’s network.
In response to the active exploitation, CISA urged authorities to patch affected systems within three days. Zimbra has released a fix in version 10.1.20, and security experts recommend that administrators either upgrade immediately or disable the snmp_notify configuration if updates cannot be applied right away.
Entities
CERT Polska · Zimbra Collaboration Suite · CISA · Microsoft · Entra ID
Timeline
-
18 days ago
[TECHNOLOGY] 3 sourcesZimbra Collaboration Suite vulnerability actively exploitedA critical command-injection vulnerability in Zimbra Collaboration Suite (CVE-2026-73570) is being actively exploited, prompting CISA to urge rapid patching to prevent remote code execution.
-
22 days ago
[TECHNOLOGY] 3 sourcesMicrosoft and Zimbra address critical security vulnerabilitiesMicrosoft patched a critical 10.0 CVSS remote code execution flaw in Entra ID, while an active exploitation campaign targets Zimbra Collaboration Suite via SMTP command injection.
Sources
algeriatech.news · cybernoz.com · dev.to · it-boltwise.de · itpro.com