
Poland's Computer Emergency Response Team (CERT Polska) has warned that a critical vulnerability in Zimbra Collaboration Suite (ZCS) is being actively exploited in attacks. The flaw, tracked as CVE-2026-73570, enables unauthenticated attackers to execute operating system commands as the Zimbra user.
The issue stems from insufficient sanitisation of untrusted input during SNMP notification processing. When SNMP notifications are enabled, an attacker can send specially crafted SMTP requests that trigger command injection and result in remote code execution. Zimbra's security team released version 10.1.20 on 20 July to patch the vulnerability.
Zimbra is widely deployed across organisations, including hundreds of government agencies. Shadowserver's monitoring currently shows more than 12,100 Zimbra servers exposed online, with 4,382 in Europe and 4,492 in Asia. The count does not indicate how many of these are honeypots or have already been patched against CVE-2026-73570.
On Monday, CERT Polska reported that threat actors are now exploiting the flaw in live attacks. The team asked administrators to check logs for suspicious activity, such as the Zimbra service restarting on its own, and for files created in the /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/ folders by user zimbra over the last 30 days.
Zimbra vulnerabilities are frequently targeted in the wild. In February 2023, the Russian Winter Vivern group used a reflected XSS exploit to steal emails from NATO-aligned individuals and organisations via Zimbra webmail portals. In October 2024, US and UK cyber agencies warned that APT29, linked to Russia's Foreign Intelligence Service, was targeting vulnerable Zimbra servers using a previously abused issue to steal email credentials. More recently, in March, Seqrite Labs reported that APT28, a state-backed group linked to Russia's military intelligence service, exploited a stored cross-site scripting vulnerability against Ukrainian government ZCS servers.
Organisations using Zimbra Collaboration Suite should update to version 10.1.20 or later and review their logs for indicators of compromise. The vulnerability allows unauthenticated remote code execution, making it a high-severity risk.
See an error? Read our corrections policy or email [email protected].
TECHNOMALIST

