Tuesday, August 25, 2026

Independent technology reporting and practical analysis

Manila ·
CYBERSECURITY

Independent reporting, useful context, and practical analysis.

Back to Technomalist
Cybersecurity / news

Critical Zimbra RCE flaw now under active exploitation, warns Polish CERT

Attackers are exploiting CVE-2026-73570, a command injection vulnerability in Zimbra Collaboration Suite that allows unauthenticated remote code execution via SNMP notifications.

Featured image for Critical Zimbra RCE flaw now under active exploitation, warns Polish CERT
Featured image for Critical Zimbra RCE flaw now under active exploitation, warns Polish CERT

Poland's Computer Emergency Response Team (CERT Polska) has warned that a critical vulnerability in Zimbra Collaboration Suite (ZCS) is being actively exploited in attacks. The flaw, tracked as CVE-2026-73570, enables unauthenticated attackers to execute operating system commands as the Zimbra user.

The issue stems from insufficient sanitisation of untrusted input during SNMP notification processing. When SNMP notifications are enabled, an attacker can send specially crafted SMTP requests that trigger command injection and result in remote code execution. Zimbra's security team released version 10.1.20 on 20 July to patch the vulnerability.

Zimbra is widely deployed across organisations, including hundreds of government agencies. Shadowserver's monitoring currently shows more than 12,100 Zimbra servers exposed online, with 4,382 in Europe and 4,492 in Asia. The count does not indicate how many of these are honeypots or have already been patched against CVE-2026-73570.

On Monday, CERT Polska reported that threat actors are now exploiting the flaw in live attacks. The team asked administrators to check logs for suspicious activity, such as the Zimbra service restarting on its own, and for files created in the /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/ folders by user zimbra over the last 30 days.

Zimbra vulnerabilities are frequently targeted in the wild. In February 2023, the Russian Winter Vivern group used a reflected XSS exploit to steal emails from NATO-aligned individuals and organisations via Zimbra webmail portals. In October 2024, US and UK cyber agencies warned that APT29, linked to Russia's Foreign Intelligence Service, was targeting vulnerable Zimbra servers using a previously abused issue to steal email credentials. More recently, in March, Seqrite Labs reported that APT28, a state-backed group linked to Russia's military intelligence service, exploited a stored cross-site scripting vulnerability against Ukrainian government ZCS servers.

Organisations using Zimbra Collaboration Suite should update to version 10.1.20 or later and review their logs for indicators of compromise. The vulnerability allows unauthenticated remote code execution, making it a high-severity risk.

See an error? Read our corrections policy or email [email protected].

MORE FROM TECHNOMALIST

Continue reading

View all
Featured image for Researchers Show Expired Visa Contactless Cards Can Be Revived for Fraud
Cybersecurity

Researchers Show Expired Visa Contactless Cards Can Be Revived for Fraud

Philips LatteGo 4400 Series espresso machine on a kitchen counter.
Guides

Philips LatteGo 4400 espresso machine drops to AU$613 on Amazon Australia

Alice talks to Nora and Frank
Entertainment

How AI and assistive tools are helping disabled actors like Steve Way thrive on 'Furious'