Ethical Hacking News
Unauthenticated remote code execution has been exposed in Zimbra Collaboration due to a previously unpatched security flaw, CVE-2026-73570, which carries a high CVSS score. Organizations using ZCS must take immediate action to patch their systems and enhance their security posture to prevent exploitation.
An unauthenticated remote code execution vulnerability, CVE-2026-73570, has been found in Zimbra Collaboration (ZCS) due to improper sanitization of untrusted input during SNMP notification processing. The vulnerability allows an attacker to send specially crafted SMTP requests, resulting in execution of arbitrary operating system commands as the Zimbra user. CERT Polska has warned of active exploitation efforts targeting the flaw, urging users to check their logs for suspicious activity. Previous vulnerabilities in Zimbra have been targeted by threat actors, including a recent phishing campaign by a Russia-linked adversary. Organizations using ZCS must patch their systems with the latest release (version 10.1.20) and implement enhanced security measures to prevent exploitation.
In recent times, numerous security breaches have plagued organizations worldwide. The latest in a series of high-profile exploits, a previously unpatched security flaw in Zimbra Collaboration (ZCS) has been actively exploited by attackers, resulting in unauthenticated remote code execution. This vulnerability, identified as CVE-2026-73570, carries a CVSS score of 8.9, making it a high-priority target for threat actors and security professionals alike.
The security issue at the heart of this exploit arises from improper sanitization of untrusted input during SNMP notification processing in ZCS. According to a description of the flaw in the NIST National Vulnerability Database (NVD), due to this oversight, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user. This situation has significant implications for the security posture of organizations relying on ZCS for their email needs.
In a recent bulletin, CERT Polska alerted of active exploitation efforts targeting the flaw, urging users to check the "/var/log/zimbra.log" file for suspicious Zimbra service restarts, as well as for files created in the below directories within the last 30 days - "/opt/zimbra/jetty/webapps/", "/opt/zimbra/jetty_base/webapps/", and "/tmp/". This directive underscores the need for prompt attention from ZCS users to ensure their systems are not inadvertently being exploited.
It's worth noting that vulnerabilities in Zimbra have been frequently targeted by threat actors. In recent months, the U.S. government disclosed details of a phishing campaign orchestrated by a Russia-linked adversary called Laundry Bear (aka CL-STA-1114, TA488, UNK_PitStop, and Void Blizzard) that involved targeting Zimbra mail servers belonging to Western government and commercial organizations since at least July 2025. This campaign was found to have weaponized CVE-2025-66376, a stored cross-site scripting vulnerability in Zimbra's Classic UI, to deliver a malicious JavaScript payload dubbed ZimReaper to harvest email communications and other sensitive data.
Given the severity of this newly exposed vulnerability and the continued threat landscape, it's imperative for organizations utilizing Zimbra Collaboration to take immediate action to rectify the situation. This involves patching the affected version of ZCS with the latest release, version 10.1.20, as well as implementing enhanced security measures to prevent similar exploitation in the future.
Unauthenticated remote code execution has been exposed in Zimbra Collaboration due to a previously unpatched security flaw, CVE-2026-73570, which carries a high CVSS score. Organizations using ZCS must take immediate action to patch their systems and enhance their security posture to prevent exploitation.
Related Information:
https://www.ethicalhackingnews.com/articles/Unauthenticated-Remote-Code-Execution-The-Zimbra-SNMP-Flaw-Exposed-ehn.shtml
https://thehackernews.com/2026/08/attackers-exploit-zimbra-snmp-flaw-for.html
https://nvd.nist.gov/vuln/detail/CVE-2026-73570
https://www.cvedetails.com/cve/CVE-2026-73570/
https://nvd.nist.gov/vuln/detail/CVE-2025-66376
https://www.cvedetails.com/cve/CVE-2025-66376/
Published: Thu Aug 20 11:02:35 2026 by llama3.2 3B Q4_K_M