Skip to finding
§
High
Remote execution — Zimbra
Confirmed
CVE-2026-73570

Zimbra servers are being compromised through SMTP input that ends up as a shell command running as the zimbra user.

Only with the optional zimbra-snmp package installed, snmp_notify enabled, and swatchdog running — which is the first thing to check, in both directions.

Affects

Zimbra Collaboration Suite, a self-hosted enterprise email and collaboration server.

What it enables

Unauthenticated operating-system command execution as the zimbra service user

Send a crafted unauthenticated SMTP request to the exposed mail service→↓Cause attacker-controlled service-status content to be processed by the enabled SNMP notification path→↓Inject an operating-system command→↓Execute the command as the zimbra service account
Why this matters

CERT Polska confirms active exploitation, unauthenticated shell execution as zimbra, the required configuration, and forensic artifacts for detection.

Detail and 3 sources
Required access

SMTP reachability to a Zimbra server with the optional zimbra-snmp package installed, snmp_notify enabled, and swatchdog running

Affected versions

Zimbra Collaboration Suite before 10.1.20 when zimbra-snmp and SNMP notifications are enabled

CERT Polska confirms active exploitation: attacker-controlled service-status text arriving over SMTP is processed by the enabled SNMP notification path, a command is injected, and it runs as the zimbra service account. Their write-up includes forensic artifacts, which is what to use if the preconditions match your install.

The preconditions are genuinely narrow — the optional zimbra-snmp package, snmp_notify turned on, swatchdog running — and that is why the reach here is niche rather than broad. It is also not a configuration most administrators can recall from memory, and recent reporting counts compromised internet-facing instances in the hundreds.

Evidence
CERT Polska confirms active exploitation, unauthenticated shell execution as zimbra, required configuration, and forensic artifactsThe CVE record identifies crafted SMTP as the input path and version 10.1.20 as the boundaryRecent reporting documented hundreds of compromised internet-facing instances
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Tuesday, September 1, 2026