CERT Polska warns attackers actively exploit critical Zimbra RCE flaw
This digest was compiled by AI from multiple sources — links to the originals are below.

CERT Polska reported Monday that threat actors are exploiting CVE-2026-73570, a critical remote code execution vulnerability in Zimbra Collaboration Suite. The flaw allows unauthenticated command injection through the SNMP monitoring component and was patched in Zimbra version 10.1.20 released July 20. Shadowserver tracks over 12,100 internet-exposed Zimbra servers, most in Europe and Asia, with no data on how many are patched.
Key Facts
- CERT Polska reported Monday that threat actors are actively exploiting CVE-2026-73570, an OS command injection flaw in Zimbra Collaboration Suite.
- Zimbra released version 10.1.20 on July 20 to patch the flaw, which allows unauthenticated remote code execution via crafted SMTP requests when SNMP notifications are enabled.
- Shadowserver tracks more than 12,100 internet-exposed Zimbra servers, including 4,382 in Europe and 4,492 in Asia.
- CERT Polska asked administrators to check logs for suspicious activity such as the Zimbra service restarting and files created by user zimbra in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/ over the past 30 days.
Active Exploitation
CERT Polska reported Monday that threat actors are actively exploiting CVE-2026-73570 in attacks. The flaw is an OS command injection vulnerability in the SNMP monitoring component of Zimbra Collaboration Suite. CERT Polska asked administrators to check logs for suspicious activity, such as the Zimbra service restarting on its own, and for files created by user zimbra in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/ over the last 30 days. Zimbra flaws are frequently targeted in the wild and have been used to breach many vulnerable email servers in recent years.
The Flaw and Patch
CVE-2026-73570 allows unauthenticated attackers to gain remote code execution by exploiting a command injection weakness when SNMP notifications are enabled. According to Zimbra, improper sanitization of untrusted input during SNMP notification processing lets an attacker send specially crafted SMTP requests to execute arbitrary operating system commands as the Zimbra user. Zimbra released version 10.1.20 on July 20 to patch the vulnerability.
Exposed Servers and Recent Attacks
Shadowserver tracks over 12,100 internet-exposed Zimbra servers, with 4,382 in Europe and 4,492 in Asia. There is no information on how many of those servers are honeypots or have already been patched against CVE-2026-73570. In February 2023, Russian Winter Vivern cyber spies used a reflected XSS exploit to steal emails from Zimbra webmail portals belonging to NATO-aligned individuals and organizations. In October 2024, US and UK cyber agencies warned that APT29 hackers were targeting vulnerable Zimbra servers by exploiting a security issue previously abused to steal email account credentials. In March, Seqrite Labs researchers said APT28 hackers exploited a stored cross-site scripting vulnerability in attacks targeting Ukrainian government Zimbra Collaboration Suite servers.
2 sources
CERT Polska warns attackers actively exploit critical Zimbra RCE flaw



