Close Menu
NCIJ Network NCIJ Network
    What's Hot

    XRP Erases Its Most Bearish Signal—And the Ripple-Linked Coin Is Flying

    August 22, 2026

    Trump’s Top Trade Representative Details Offer That Canada Refused

    August 22, 2026

    You can instantly curate your Discover feed now by telling Google exactly what you want

    August 22, 2026
    Facebook X (Twitter) Instagram
    Trending
    • XRP Erases Its Most Bearish Signal—And the Ripple-Linked Coin Is Flying
    • Trump’s Top Trade Representative Details Offer That Canada Refused
    • You can instantly curate your Discover feed now by telling Google exactly what you want
    • Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution
    • Bitcoin ETFs Just Had Their Biggest Day Since May—BlackRock Took 83% of It
    • JWST finds early galaxies may be 4 times more massive than thought
    • Seventeen-year-old girl killed in sword attack at school in Sweden | Sweden
    • An okay laptop with 16GB of RAM is better than a nice laptop with 8GB, and this $520 HP OmniBook proves it
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, August 22
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 22, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananAug 20, 2026Vulnerability / Email Security

    A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency Response Team (CERT Polska).

    The vulnerability in question is CVE-2026-73570 (CVSS score: 8.9), which refers to a case of command injection that can lead to remote code execution.

    “A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed, and SNMP notifications are enabled,” according to a description of the flaw in the NIST National Vulnerability Database (NVD).

    “Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.”

    The security issue was patched by Zimbra last month with the release of version 10.1.20.

    Cybersecurity

    In a bulletin issued earlier this week, CERT Polska alerted of active exploitation efforts targeting the flaw, urging users to check the “/var/log/zimbra.log” file for suspicious Zimbra service restarts, as well as for files created in the below directories within the last 30 days –

    • /opt/zimbra/jetty/webapps/
    • /opt/zimbra/jetty_base/webapps/
    • /tmp/

    Vulnerabilities in Zimbra have been frequently targeted by threat actors. Last month, the U.S. government disclosed details of a phishing campaign orchestrated by a Russia-linked adversary called Laundry Bear (aka CL-STA-1114, TA488, UNK_PitStop, and Void Blizzard) that involved targeting Zimbra mail servers belonging to Western government and commercial organizations since at least July 2025.

    The campaign was found to have weaponized CVE-2025-66376, a stored cross-site scripting vulnerability in Zimbra’s Classic UI, to deliver a malicious JavaScript payload dubbed ZimReaper to harvest email communications and other sensitive data.

    Update

    On August 21, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-73570 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes for the flaw by August 24, 2026.

    (The story was updated after publication on August 22, 2026, to include details of the CVE identifiers and their addition to CISA’s KEV catalog.)

    Attackers Code Execution exploit Flaw remote SNMP unauthenticated Zimbra
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers

    Microsoft Fixes ‘Perfect 10’ Exploit That Could Have Let Hackers Run Code Remotely

    TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit

    Named Pipes Under Attack: Securing Windows Interprocess Communication

    Hackers infect Android car head units with proxy botnet malware

    Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    XRP Erases Its Most Bearish Signal—And the Ripple-Linked Coin Is Flying

    August 22, 2026

    Trump’s Top Trade Representative Details Offer That Canada Refused

    August 22, 2026

    You can instantly curate your Discover feed now by telling Google exactly what you want

    August 22, 2026

    Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution

    August 22, 2026
    Latest Posts

    Satirical fake Guardian front page on ‘genetic links’ between eating bacon and far-right activism shared as genuine – Full Fact

    July 28, 2026

    U.S. Foreign Policy Must Prioritize Human Rights

    July 28, 2026

    Madison revisits police body cameras after years of debate

    July 28, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    XRP Erases Its Most Bearish Signal—And the Ripple-Linked Coin Is Flying

    August 22, 2026

    Trump’s Top Trade Representative Details Offer That Canada Refused

    August 22, 2026

    You can instantly curate your Discover feed now by telling Google exactly what you want

    August 22, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.