轉發 國家資安資訊分享與分析中心 資安訊息警訊 NISAC-200-202609-00000003
[內容說明]
研究人員發現Zimbra Collaboration存在作業系統指令注入(OS Command Injection)漏洞(CVE-2026-73570),當系統安裝選用套件zimbra-snmp並啟用SNMP通知功能時,未經身分鑑別之遠端攻擊者可藉由傳送特製SMTP請求,以Zimbra使用者權限執行任意作業系統指令。該漏洞已遭駭客利用,請儘速確認並進行修補。
[影響平台]
Zimbra Collaboration 10.1.20(不含)以前版本
[建議措施]
官方已針對漏洞釋出修補程式,請升級Zimbra Collaboration至10.1.20(含)以後版本。 詳細說明請參考官方公告,網址如下: https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
[參考資料]
1. https://nvd.nist.gov/vuln/detail/CVE-2026-73570
2. https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-73570
3. https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
Forwarded from National Information Sharing and Analysis Center Cybersecurity Information Alert NISAC-200-202609-00000003
[Content Description]
Researchers discovered that Zimbra Collaboration contains an OS Command Injection vulnerability(CVE-2026-73570). When the optional package zimbra-snmp is installed and the SNMP notification function is enabled, unauthenticated remote attackers can execute arbitrary operating system commands with Zimbra user privileges by sending specially crafted SMTP requests. This vulnerability has been exploited by hackers. Please confirm and patch as soon as possible.
[Affected Platforms]
Zimbra Collaboration versions 10.1.20(exclusive) and earlier
[Recommended Measures]
The official source has released a patch for the vulnerability. Please upgrade Zimbra Collaboration to version 10.1.20(inclusive) or later. For detailed information, please refer to the official advisory at the following URL: https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
[References]
1. https://nvd.nist.gov/vuln/detail/CVE-2026-73570
2. https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-73570
3. https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories