Critical Zimbra RCE flaw now actively exploited in attacks

A critical vulnerability in Zimbra Collaboration Suite (ZCS) has been actively exploited by attackers, putting hundreds of millions of users worldwide at risk. The Polish Computer Emergency Response Team (CERT Polska) has warned that unauthenticated attackers can gain remote code execution by exploiting a command injection weakness in the SNMP monitoring component when SNMP notifications are enabled.

The vulnerability, tracked as CVE-2026-73570, was patched by Zimbra’s security team in version 10.1.20 on July 20. However, it appears that many organizations have yet to apply the patch, leaving their email and collaboration servers exposed to attack. CERT Polska has reported that threat actors are now actively exploiting this flaw, and Shadowserver estimates that over 12,100 Zimbra servers are exposed online, with most located in Europe and Asia.

ZCS is a popular email and collaboration software suite used by thousands of businesses and hundreds of government agencies worldwide. The software allows users to send SNMP notifications, which can be exploited by attackers if they are not properly configured or patched. When an attacker sends specially crafted SMTP requests, they can execute arbitrary operating system commands as the Zimbra user.

The exploitation of this vulnerability is particularly concerning given its potential impact on sensitive information and systems. As we’ve seen in recent years, vulnerabilities in Zimbra have been frequently targeted by attackers, including state-backed groups such as APT28 and APT29. These groups have used Zimbra flaws to breach email servers, steal credentials, and gain access to sensitive data.

To mitigate this risk, administrators are advised to check their logs for suspicious activity, such as the Zimbra service restarting on its own or files being created in specific folders by user zimbra over the last 30 days. They should also ensure that SNMP notifications are disabled or properly configured, and apply the latest security patches to prevent exploitation of this vulnerability.

In conclusion, the active exploitation of the CVE-2026-73570 vulnerability highlights the importance of staying up-to-date with security patches and configuring software settings carefully. Users of Zimbra Collaboration Suite should take immediate action to secure their email and collaboration servers by applying the latest patch and reviewing their logs for potential signs of compromise.


Source: Bleeping Computer — 2026-08-20