< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [TECHNOLOGY]

2 clusters · 5 sources · 4 days · First seen · Last updated

Zimbra Collaboration Suite security vulnerability

Overview

A critical security vulnerability in the Zimbra Collaboration Suite, identified as CVE-2026-73570, has been identified as a significant threat. The flaw allows unauthenticated attackers to execute operating system commands by sending crafted SMTP requests to servers with SNMP notifications enabled.

Initial reports indicated the vulnerability was being actively exploited. Subsequent details clarified that the risk is particularly high because the swatchdog service is enabled by default on many installations. Successful exploitation can allow attackers to deploy web shells, steal email data, or establish persistence within an organization’s network.

In response to the active exploitation, CISA urged authorities to patch affected systems within three days. Zimbra has released a fix in version 10.1.20, and security experts recommend that administrators either upgrade immediately or disable the snmp_notify configuration if updates cannot be applied right away.

Entities

CERT Polska · Zimbra Collaboration Suite · CISA · Microsoft · Entra ID

Timeline

  1. 18 days ago

    [TECHNOLOGY] 3 sources
    Zimbra Collaboration Suite vulnerability actively exploited

    A critical command-injection vulnerability in Zimbra Collaboration Suite (CVE-2026-73570) is being actively exploited, prompting CISA to urge rapid patching to prevent remote code execution.

  2. 22 days ago

    [TECHNOLOGY] 3 sources
    Microsoft and Zimbra address critical security vulnerabilities

    Microsoft patched a critical 10.0 CVSS remote code execution flaw in Entra ID, while an active exploitation campaign targets Zimbra Collaboration Suite via SMTP command injection.

Sources

algeriatech.news · cybernoz.com · dev.to · it-boltwise.de · itpro.com