Critical Zimbra Vulnerabilities, Including One Actively Exploited, Allow Remote Code Execution

AI-generated NewsSnap summary based on source reporting.
Published: 2026-08-24
Category: technology
Source: HKCert

Multiple critical vulnerabilities have been identified in Zimbra, including CVE-2026-73570, which is actively being exploited in the wild. This vulnerability could allow an unauthenticated attacker to execute arbitrary operating system commands as the Zimbra user by sending specially crafted SMTP requests, particularly if the optional zimbra-snmp package is installed and SNMP notifications are enabled. Other vulnerabilities could lead to cross-site scripting, sensitive information disclosure, and security restriction bypass.

Want more?

Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.

Open NewsSnap.ai