www.securityweek.com 8/20/2026, 3:32:04 PM · external

Zimbra CVE-2026-73570 bug lets attackers run OS commands

Zimbra CVE-2026-73570 bug lets attackers run OS commands
Developing story malware 2 articles tracked
Zimbra Collaboration RCE vulnerability (CVE-2026-73570) exploited in the wild
CyberSIXT Evidence Panel
Primary Source moje.cert.pl
CISA KEV Not in KEV
Patch Patch Status Unknown

A high-severity vulnerability in Zimbra Collaboration Suite (CVE-2026-73570) is actively being exploited, as reported by CERT Polska. This flaw occurs when the 'zimbra-snmp' package is installed, allowing attackers to execute arbitrary OS commands without authentication. The vulnerability was patched in version 10.1.20 released on July 20, 2026.

The threat actors targeting this vulnerability remain unidentified, but its exploitation can lead to unauthorized control over the Zimbra server, compromising email accounts and credentials. Related vulnerabilities have been linked to state-sponsored hackers from Russia and China. This specific vulnerability is not yet included in CISA’s catalog of known exploited vulnerabilities.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline