← All articles

Attackers exploit unauthenticated Zimbra SNMP flaw for remote code execution

Poland's national CERT warned that attackers are exploiting a now-patched flaw in Zimbra Collaboration to run commands on mail servers without authentication. Tracked as CVE-2026-73570 and scored 8.9, it is an OS command injection bug in Zimbra's SNMP monitoring feature: when the optional SNMP package is installed and notification traps are enabled, improper input handling lets an unauthenticated attacker send crafted requests that execute commands as the Zimbra user. The monitoring service involved is on by default where SNMP is used, widening exposure. Zimbra fixed it in version 10.1.20 in July, and Zimbra servers are a long-standing target, so unpatched instances should be treated as urgent.

Check
Update Zimbra Collaboration to 10.1.20 or later now, and check whether the SNMP package is installed with notifications enabled, which is the exposed configuration under active attack.
Affected
Organizations running Zimbra Collaboration before 10.1.20 with the SNMP package installed and notifications enabled (CVE-2026-73570); an unauthenticated attacker can execute operating-system commands as the Zimbra user, and exploitation is underway.
Fix
Patch to 10.1.20, and if you ran an exposed version, inspect the Zimbra log for suspicious service restarts and recently created files, since patching alone will not evict a foothold.