← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 24, 2026 · 17:04via Cyber Security News

Zimbra Collaboration Suite Vulnerability Actively Exploited in the Wild

Brief

CERT Polska has warned that threat actors are actively exploiting CVE-2026-73570 , a critical OS command-injection vulnerability in Zimbra Collaboration Suite that allows remote, unauthenticated attackers to execute arbitrary shell commands as the zimbra user.

The vulnerability affects Zimbra installations in which the SNMP trap service is enabled via the snmp_notify parameter and the swatchdog service is running.

Since swatchdog is enabled by default, exposed servers with SNMP notifications configured may face a heightened risk of compromise. Successful exploitation could give attackers a foothold on vulnerable mail servers without requiring valid credentials.

From there, attackers may execute malicious commands , create or modify files, deploy web shells, steal email data, establish persistence, or use the compromised server to target other systems within an organization.

Read more on Cyber Security News