Skip to main content
Emerging ThreatsMalware & Ransomware

Zimbra Vulnerability Exploited in Active Attacks

Rows of office mailboxes or server equipment with a single workstation and blank laptop screen in the foreground.

Over 12,100 Zimbra Collaboration Suite (ZCS) servers are exposed online, most of them in Europe (4,382) and Asia (4,492), and Polish national CERTs now say attackers are actively exploiting a critical remote code execution flaw tracked as CVE-2026-73570.

CVE-2026-73570: a command-injection path through SNMP notifications

The vulnerability, disclosed and patched by the Zimbra security team in version 10.1.20 on July 20, permits unauthenticated attackers to achieve remote code execution. Zimbra described the root cause as “improper sanitization of untrusted input during SNMP notification processing,” and said an attacker can “send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.” The risky component is SNMP monitoring when SNMP notifications are enabled; exploitation is an OS command injection rather than a simple information leak.

CERT Polska: actively exploited and concrete indicators to hunt for

On Monday the Polish Computer Emergency Response Team (CERT Polska) warned that threat actors are “now exploiting CVE-2026-73570 in attacks.” CERT Polska explicitly described the flaw as an “actively used OS Command Injection vulnerability in the Zimbra Collaboration Suite” and urged administrators to check recent logs and artifacts. Specifically, they asked teams to look for unexpected Zimbra service restarts and for files created by the zimbra user over the last 30 days in these locations: /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/.

Scale of exposure: Shadowserver’s internet-wide snapshot and an important unknown

Internet security watchdog Shadowserver reports more than 12,100 Zimbra servers reachable from the public internet. The source material notes there is no information on how many of those hosts are honeypots or have already been patched against CVE-2026-73570, leaving a substantial and unquantified risk surface. The Zimbra suite itself is widespread: the notice describes ZCS as used by “hundreds of millions of people and organizations worldwide,” including thousands of businesses and hundreds of government agencies, amplifying the potential consequences of successful exploitation.

Context: repeated Zimbra targeting by named threat actors

Zimbra deployments have been targeted repeatedly in recent years by sophisticated operators. The source record cites several episodes: in February 2023, Russian group Winter Vivern used a reflected XSS exploit to steal emails from NATO-aligned targets; in October 2024, U.S. and U.K. cyber agencies warned that APT29 (also tracked as Midnight Blizzard and Cozy Bear and linked to Russia’s Foreign Intelligence Service) was exploiting a prior Zimbra flaw to steal credentials; and in March, Seqrite Labs reported APT28 using a stored cross-site scripting vulnerability against Ukrainian government ZCS servers. Those precedents underline both attacker interest in Zimbra and the variety of techniques—XSS and credential theft as well as command injection—that adversaries will employ.

What this means for technologists, affected enterprises and government agencies, and adversaries

  • Technologists and security teams: confirm whether SNMP notifications are enabled, apply Zimbra 10.1.20 where appropriate, and hunt for the specific indicators CERT Polska recommended—service restarts and files created by the zimbra user in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/ within the last 30 days.
  • Affected enterprises and government agencies: prioritize inventories of externally reachable Zimbra servers (Shadowserver’s >12,100 count is a starting point), validate patch status, and consider whether exposed instances must be shielded or taken offline until patched—especially since ZCS is widely used across businesses and government entities.
  • Adversaries and threat actors: past campaigns show a willingness to chain web-based and credential-based techniques against Zimbra; the existence of an unauthenticated RCE in SNMP notification handling provides a low-bar exploitation path that actors may continue to weaponize.

The immediate technical remedy is clear — Zimbra released 10.1.20 on July 20 to address CVE-2026-73570 — but the operational questions remain. Shadowserver’s public-facing count shows a large footprint, CERT Polska reports active exploitation, and the past pattern of Zimbra-targeted operations suggests motivated actors will continue to probe and to turn initial access into data theft. The open question for defenders is measurable: how many of those 12,100+ reachable servers have already been patched or are traps, and how many will report the telltale artifacts CERT Polska lists?

Read the original advisory and reporting: https://www.bleepingcomputer.com/news/security/critical-zimbra-rce-flaw-now-actively-exploited-in-attacks/

Zimbra Vulnerability Exploited in Active Attacks | OSINTSights