Particle.news

Attackers Actively Exploit Critical Zimbra Remote‑Code‑Execution Flaw

The bug lets unauthenticated SMTP requests execute OS commands as the zimbra user, creating an urgent need for patching or disabling SNMP notifications to prevent email theft and network compromise.

Overview

  • Zimbra released a fix in version 10.1.20 on July 20 for CVE-2026-73570, a command‑injection flaw in the SNMP notification component that permits unauthenticated remote code execution.
  • CERT Polska reported active exploitation Thursday, saying attackers send crafted SMTP requests that inject commands into SNMP notification processing and run with zimbra user privileges.
  • Internet scans by Shadowserver show more than 12,100 Zimbra servers reachable online, though it is unknown how many are unpatched, honeypots, or already compromised.
  • Administrators are urged to urgently install ZCS 10.1.20 or disable SNMP notifications, and to hunt for indicators such as unexpected Zimbra service restarts, files owned by zimbra in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/ or /tmp/, child processes spawned by snmp_notify, and unusual outbound connections.
  • If exploited, attackers can place web shells, harvest credentials, steal email and move laterally inside networks, a pattern seen before when state‑linked groups and criminals targeted Zimbra servers.