Zimbra servers are being compromised through SMTP input that ends up as a shell command running as the zimbra user.
Only with the optional zimbra-snmp package installed, snmp_notify enabled, and swatchdog running — which is the first thing to check, in both directions.
Zimbra Collaboration Suite, a self-hosted enterprise email and collaboration server.
Unauthenticated operating-system command execution as the zimbra service user
CERT Polska confirms active exploitation, unauthenticated shell execution as zimbra, the required configuration, and forensic artifacts for detection.
Detail and 3 sources
CERT Polska confirms active exploitation: attacker-controlled service-status text arriving over SMTP is processed by the enabled SNMP notification path, a command is injected, and it runs as the zimbra service account. Their write-up includes forensic artifacts, which is what to use if the preconditions match your install.
The preconditions are genuinely narrow — the optional zimbra-snmp package, snmp_notify turned on, swatchdog running — and that is why the reach here is niche rather than broad. It is also not a configuration most administrators can recall from memory, and recent reporting counts compromised internet-facing instances in the hundreds.
- access:network:internet
- reachable from the public internet
- interaction:none
- no user action required
- Reaches end-of-life hardware
- No
Scope: this answers for the patched 10.1.20 SNMP notification path I could read; rollback enforcement and alternate-interface completeness were not established.