AI Security AI安全 1d ago Updated 1d ago 更新于 1天前 42

Hackers Target Zimbra Servers in Active Exploitation Campaign 黑客在活跃利用活动中针对Zimbra服务器

CVE-2026-73570 is a high-severity, unauthenticated remote code execution vulnerability in Zimbra Collaboration Suite affecting installations with the optional zimbra-snmp package and SNMP notifications enabled The vulnerability was patched in Zimbra version 10.1.20, released on July 20, but is already being actively exploited in the wild according to Poland's CERT Polska Attackers can execute arbitrary OS commands as the Zimbra user without any authentication, potentially gaining full server con Zimbra Collaboration存在高严重性漏洞CVE-2026-73570,已在版本10.1.20中修复 漏洞允许未认证攻击者通过SNMP功能执行任意操作系统命令 波兰CERT观察到该漏洞正在被积极利用,攻击者可完全控制服务器 攻击者可能窃取凭证、建立持久性并横向移动到其他系统 此类漏洞利用常与俄罗斯和中国国家支持的黑客组织相关

65
Hot 热度
60
Quality 质量
55
Impact 影响力

Analysis 深度分析

TL;DR

  • CVE-2026-73570 is a high-severity, unauthenticated remote code execution vulnerability in Zimbra Collaboration Suite affecting installations with the optional zimbra-snmp package and SNMP notifications enabled
  • The vulnerability was patched in Zimbra version 10.1.20, released on July 20, but is already being actively exploited in the wild according to Poland's CERT Polska
  • Attackers can execute arbitrary OS commands as the Zimbra user without any authentication, potentially gaining full server control, establishing persistence, harvesting credentials, and moving laterally
  • CISA's Known Exploited Vulnerabilities (KEV) catalog currently lists 18 Zimbra Collaboration Suite vulnerabilities, with four added this year, but CVE-2026-73570 has not yet been added
  • Zimbra exploitation has historically been linked to both Russian and Chinese state-sponsored actors targeting military and diplomatic intelligence, as well as opportunistic cybercriminals

Why It Matters

This vulnerability is critical for any organization running Zimbra Collaboration Suite with SNMP enabled, as it allows unauthenticated attackers to achieve full remote code execution — a direct path to complete server compromise. The active exploitation in the wild, combined with Zimbra's history as a target for both nation-state and criminal actors, makes immediate patching and SNMP remediation essential for enterprise email infrastructure security.

Technical Details

  • Vulnerability: CVE-2026-73570, a high-severity unauthenticated RCE flaw in Zimbra Collaboration Suite
  • Attack vector: Exploitable when the optional zimbra-snmp package is installed and SNMP notifications are enabled; no authentication required
  • Impact: Arbitrary OS command execution as the Zimbra user, enabling full server compromise, persistence, credential harvesting, and lateral movement
  • Patch: Zimbra version 10.1.20, released July 20
  • Context: CISA KEV catalog includes 18 prior Zimbra vulnerabilities (4 added this year); CVE-2026-73570 is not yet listed

Industry Insight

  • Organizations running Zimbra should immediately disable the zimbra-snmp package or SNMP notifications if patching cannot be applied instantly, and prioritize upgrading to version 10.1.20
  • Given the pattern of Zimbra exploitation by both state-sponsored and criminal actors, enterprises should assume active compromise is possible and conduct thorough IoC-based hunting across their environments
  • This incident reinforces the importance of CISA KEV catalog monitoring and rapid patching workflows for enterprise collaboration platforms, especially those with unauthenticated RCE potential

TL;DR

  • Zimbra Collaboration存在高严重性漏洞CVE-2026-73570,已在版本10.1.20中修复
  • 漏洞允许未认证攻击者通过SNMP功能执行任意操作系统命令
  • 波兰CERT观察到该漏洞正在被积极利用,攻击者可完全控制服务器
  • 攻击者可能窃取凭证、建立持久性并横向移动到其他系统
  • 此类漏洞利用常与俄罗斯和中国国家支持的黑客组织相关

为什么值得看

这篇文章揭示了企业级协作平台的关键安全漏洞正在被实际利用,对使用Zimbra的组织和IT安全从业者具有重要警示意义。

技术解析

  • 漏洞编号:CVE-2026-73570,高严重性
  • 触发条件:安装可选的'zimbra-snmp'包并启用SNMP通知
  • 攻击影响:无需认证即可执行任意OS命令,攻击者可获得Zimbra用户权限
  • 修复版本:Zimbra Collaboration 10.1.20(2024年7月20日发布)
  • CISA KEV目录已收录18个Zimbra相关漏洞

行业启示

  • 企业应及时更新Zimbra至10.1.20或更高版本,并审查SNMP配置
  • 建议组织检查是否存在未认证的远程代码执行风险,特别是启用SNMP功能的系统
  • 应建立持续的漏洞监控和应急响应机制,防范类似漏洞被利用的风险

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 Open Source 开源