← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 24, 2026 · 07:47via CyberPress

Actively Exploited Zimbra Flaw Lets Unauthenticated Attackers Execute Shell Commands

Brief

A newly disclosed active exploitation targeting a critical OS command injection vulnerability in Zimbra Collaboration Suite that enables unauthenticated remote attackers to execute arbitrary shell commands as the zimbra user.

Tracked as CVE-2026-73570 , the vulnerability affects Zimbra instances where SNMP trap notifications are enabled through the snmp_notify parameter and the swatchdog service is active.

Because swatchdog is enabled by default, organizations operating Zimbra environments with the relevant SNMP configuration may be exposed to remote compromise.

Actively Exploited Zimbra Flaw

The flaw has been addressed in Zimbra Collaboration Suite version 10.

  • 20. CERT Polska urged administrators to immediately verify the version deployed in their environments and update all affected systems to the fixed release.
Read more on CyberPress