Skip to content
Tech News
← Back to articles

Critical Zimbra RCE flaw now actively exploited in attacks

read original more articles
Why This Matters

The active exploitation of a critical remote code execution vulnerability in Zimbra Collaboration Suite underscores the urgent need for organizations to update their systems. As Zimbra remains a widely used platform, this flaw poses significant risks to data security and operational integrity across various sectors. Prompt patching and vigilant monitoring are essential to prevent potential breaches and mitigate the impact of ongoing attacks.

Key Takeaways

CERT Polska, the Polish Computer Emergency Response Team (CERT), warned that attackers have begun exploiting a critical vulnerability in Zimbra Collaboration Suite (ZCS).

ZCS is a popular email and collaboration software suite used by hundreds of millions of people and organizations worldwide, including thousands of businesses and hundreds of government agencies.

The Zimbra security team released version 10.1.20 on July 20 to patch the vulnerability (tracked as CVE-2026-73570), which allows unauthenticated attackers to gain remote code execution by exploiting a command injection weakness in the SNMP monitoring component when SNMP notifications are enabled.

"Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user," it explained.

Internet security watchdog Shadowserver now tracks over 12,100 Zimbra servers exposed online, most of them in Europe (4,382) and Asia (4,492).

However, there is no information on how many of them are honeypots or have already been patched against the CVE-2026-73570 security flaw.

Internet-exposed Zimbra servers (Shadowserver)

​Flagged as actively exploited

On Monday, the Polish CERT team reported that threat actors are now exploiting CVE-2026-73570 in attacks.

"The CERT Polska team reports on an actively used OS Command Injection vulnerability in the Zimbra Collaboration Suite," it warned.

... continue reading