< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-08-20T18:54:28+05:30

Zimbra SNMP Flaw Exploited for Unauthenticated Remote Code Execution

A critical vulnerability (CVE-2026-73570) in Zimbra Collaboration's SNMP component enables unauthenticated remote code execution due to command injection, actively exploited in the wild. The flaw was patched in version 10.1.20, with advisories warning of malicious activity targeting affected systems.

A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency Response Team (CERT Polska).

The vulnerability in question is CVE-2026-73570 (CVSS score: 8.9), which refers to a case of command injection that can lead to remote code execution.

"A remote code execution vulnerability exists in Zimbra

Read original article

*** END OF TRANSMISSION ***