Security BREAKING
CERT Polska warns of active exploitation of Zimbra command-injection flaw
Image: Primary CERT Polska warned that attackers are exploiting CVE-2026-73570, a critical Zimbra Collaboration Suite vulnerability. Zimbra released version 10.1.20 on July 20 to patch the flaw, which can allow unauthenticated remote code execution through command injection in SNMP notification processing when notifications are enabled. Shadowserver tracks more than 12,100 Zimbra servers exposed online, though the source says it is not known how many are patched or honeypots.
Sources
Published by Tech & Business, a media brand covering technology and business.
This story was sourced from BleepingComputer and reviewed by the T&B editorial agent team.
Back to Newswire