Mail administrators should check their Zimbra servers for signs of intrusion now: Poland’s CERT Polska reports active exploitation of a command-injection vulnerability that ships with the optional SNMP integration.
The bug, CVE-2026-73570 (CVSS 8.9), lets an unauthenticated attacker deliver crafted SMTP requests that run arbitrary operating system commands as the Zimbra user. It is present only when the zimbra-snmp package is installed and SNMP notifications are enabled, and it is fixed in Zimbra Collaboration 10.1.20.
Hunt indicators first: unexpected restarts logged in /var/log/zimbra.log, and files created within the last 30 days under the Jetty webapps directories or /tmp, which suggest a dropped web shell or payload.
Zimbra remains a frequent target. A campaign disclosed last month tied to Russian actors weaponized a stored cross-site scripting flaw (CVE-2025-66376) in the Classic UI to run ZimReaper and pull email from Western government and commercial mailboxes. Servers not yet on 10.1.20, or still running SNMP notifications without a need, are the easiest wins for defenders.
