
Actively Exploited Zimbra Flaw Lets Unauthenticated Attackers Execute Shell Commands
A newly disclosed active exploitation targeting a critical OS command injection vulnerability in Zimbra Collaboration Suite that enables unauthenticated remote attackers to execute arbitrary shell commands as the zimbra user. Tracked as CVE-2026-73570, the vulnerability affects Zimbra instances where SNMP trap notifications are enabled through the snmp_notify parameter and the swatchdog service is active. Because […]
The post Actively Exploited Zimbra Flaw Lets Unauthenticated Attackers Execute Shell Commands appeared first on Cyber Security News.