Zimbra mail servers under fire as SNMP bug gets exploited

Poland's CERT warns attackers are exploiting a patched Zimbra command-injection flaw in the wild.

CSBadmin
1 Min Read

Mail administrators should check their Zimbra servers for signs of intrusion now: Poland’s CERT Polska reports active exploitation of a command-injection vulnerability that ships with the optional SNMP integration.

The bug, CVE-2026-73570 (CVSS 8.9), lets an unauthenticated attacker deliver crafted SMTP requests that run arbitrary operating system commands as the Zimbra user. It is present only when the zimbra-snmp package is installed and SNMP notifications are enabled, and it is fixed in Zimbra Collaboration 10.1.20.

Hunt indicators first: unexpected restarts logged in /var/log/zimbra.log, and files created within the last 30 days under the Jetty webapps directories or /tmp, which suggest a dropped web shell or payload.

Zimbra remains a frequent target. A campaign disclosed last month tied to Russian actors weaponized a stored cross-site scripting flaw (CVE-2025-66376) in the Classic UI to run ZimReaper and pull email from Western government and commercial mailboxes. Servers not yet on 10.1.20, or still running SNMP notifications without a need, are the easiest wins for defenders.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.