A critical vulnerability in Zimbra Collaboration Suite (ZCS) has been exploited in real-world attacks, leaving hundreds of millions of users vulnerable. The flaw, tracked as CVE-2026-73570, allows unauthenticated attackers to gain remote code execution by exploiting a command injection weakness in the SNMP monitoring component when notifications are enabled.
The vulnerability was patched by Zimbra on July 20 with version 10.1.20, but it appears that many organizations have yet to update their systems. Internet security watchdog Shadowserver estimates that over 12,100 Zimbra servers are exposed online, with most of them located in Europe and Asia. However, it’s unclear how many of these servers are honeypots or have already been patched against the vulnerability.
The Polish Computer Emergency Response Team (CERT Polska) has reported that threat actors are actively exploiting CVE-2026-73570 to gain unauthorized access to Zimbra email and collaboration platforms. CERT Polska warns admins to check their logs for suspicious activity, such as the Zimbra service restarting on its own, and for files created in specific folders by the user “zimbra” over the last 30 days.
This is not an isolated incident – Zimbra vulnerabilities have been frequently targeted by attackers in recent years. For instance, Russian cyber spies used a reflected XSS exploit to steal emails from NATO-aligned individuals and organizations with Zimbra webmail portals in February 2023. Similarly, APT29 hackers were warned for targeting vulnerable Zimbra servers in October 2024, exploiting a security issue previously abused to steal email account credentials.
The severity of the vulnerability is compounded by the fact that once attackers gain valid credentials, only 37% of their actions are blocked. This highlights the importance of prioritizing patching and updating systems as soon as possible, rather than relying on prevention measures alone. As seen in recent reports, prevention scores can hide what happens after initial access, making it crucial for admins to stay vigilant and proactive.
For those affected by this vulnerability, it’s essential to take immediate action to protect your Zimbra servers. This includes updating to the latest version of ZCS (10.1.20) as soon as possible, reviewing system logs for suspicious activity, and conducting regular security audits to identify potential vulnerabilities.
Source: Bleeping Computer — 2026-08-20