Overview
- Zimbra released a fix in version 10.1.20 on July 20 for CVE-2026-73570, a command‑injection flaw in the SNMP notification component that permits unauthenticated remote code execution.
- CERT Polska reported active exploitation Thursday, saying attackers send crafted SMTP requests that inject commands into SNMP notification processing and run with zimbra user privileges.
- Internet scans by Shadowserver show more than 12,100 Zimbra servers reachable online, though it is unknown how many are unpatched, honeypots, or already compromised.
- Administrators are urged to urgently install ZCS 10.1.20 or disable SNMP notifications, and to hunt for indicators such as unexpected Zimbra service restarts, files owned by zimbra in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/ or /tmp/, child processes spawned by snmp_notify, and unusual outbound connections.
- If exploited, attackers can place web shells, harvest credentials, steal email and move laterally inside networks, a pattern seen before when state‑linked groups and criminals targeted Zimbra servers.