Attackers Exploit Critical Zimbra Vulnerability in Active Cyberattacks
Poland’s Computer Emergency Response Team, CERT Polska, is warning administrators that attackers are actively exploiting a critical command injection vulnerability in the Zimbra Collaboration Suite (ZCS).
Zimbra Collaboration Suite is a widely used email and collaboration platform deployed by businesses, government agencies, and other organizations around the world. The newly exploited flaw could allow unauthenticated attackers to execute operating system commands remotely on vulnerable servers.
The Zimbra Security Team released Zimbra version 10.1.20 on July 20 to address the vulnerability, tracked as CVE-2026-73570.
When SNMP notifications are enabled, the vulnerability allows an unauthenticated attacker to exploit the Zimbra SNMP monitoring component through specially crafted input and execute arbitrary commands with the privileges of the Zimbra user.
According to the vulnerability description, “Untrusted input was improperly sanitized during SNMP notification processing,” potentially allowing attackers to send a specially crafted request and execute arbitrary operating system commands as the Zimbra user.
Internet security organization Shadowserver is currently tracking more than 12,100 internet-exposed Zimbra servers. Most are located in Europe, with 4,382 servers, and Asia, with 4,492 servers.
Shadowserver’s data does not indicate how many of these systems are honeypots or whether they have been updated to protect against CVE-2026-73570.

CVE-2026-73570 Exploited in the Wild
On Monday, CERT Polska confirmed that threat actors are actively exploiting CVE-2026-73570 in attacks against Zimbra Collaboration Suite servers.
“The CERT Polska team has reported an OS command injection vulnerability that is actively used in Zimbra Collaboration Suite,” the agency warned.
Administrators should immediately update vulnerable Zimbra installations to a version containing the security fix. CERT Polska also recommends reviewing server logs for signs of compromise, including unexpected Zimbra service restarts and files created by the zimbra user during the past 30 days.
In particular, administrators should inspect the following directories for suspicious or recently created files:
/opt/zimbra/jetty/webapps//opt/zimbra/jetty_base/webapps//tmp/
Zimbra vulnerabilities are frequently targeted because exposed email servers can provide attackers with access to sensitive communications, user credentials, and internal systems.
In February 2023, the Russian cyberespionage group Winter Vivern used a reflected cross-site scripting (XSS) vulnerability to steal emails from NATO-affiliated individuals and organizations through the Zimbra webmail portal.
In October 2024, cybersecurity agencies in the United States and United Kingdom warned that APT29, also known as Midnight Blizzard and Cozy Bear, was targeting vulnerable Zimbra servers. The group is linked to Russia’s Foreign Intelligence Service and had exploited Zimbra flaws to steal email account credentials.
More recently, researchers at Seqrite Labs reported that APT28, a Russian state-sponsored threat group associated with the country’s military intelligence service, exploited a stored cross-site scripting vulnerability in attacks against Ukrainian government Zimbra Collaboration Suite servers.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




