# CERT Polska warns of active exploitation of Zimbra command-injection flaw

_Thursday, August 20, 2026 at 5:46 AM EDT · Security · Breaking · Tier 1 — Major_

![CERT Polska warns of active exploitation of Zimbra command-injection flaw — Primary](https://www.bleepstatic.com/content/hl-images/2026/07/10/Zimbra-headpic.jpg)

CERT Polska warned that attackers are exploiting CVE-2026-73570, a critical Zimbra Collaboration Suite vulnerability. Zimbra released version 10.1.20 on July 20 to patch the flaw, which can allow unauthenticated remote code execution through command injection in SNMP notification processing when notifications are enabled. Shadowserver tracks more than 12,100 Zimbra servers exposed online, though the source says it is not known how many are patched or honeypots.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/critical-zimbra-rce-flaw-now-actively-exploited-in-attacks/)

---
Canonical: https://techandbusiness.org/newswire/EPamn5JqXsO445oul1OinI
Retrieved: 2026-08-20T12:06:38.780Z
Publisher: Tech & Business (techandbusiness.org)
