Critical Zimbra RCE Vulnerability Actively Exploited in Cyber Attacks
Critical Zimbra RCE flaw now actively exploited in attacks
Vulnerability Details
A critical vulnerability in Zimbra Collaboration Suite (ZCS) has been identified as actively exploited by threat actors, according to warnings from CERT Polska, the Polish Computer Emergency Response Team. ZCS, a widely used collaboration platform, serves millions of users globally, including enterprises and government entities. The flaw, designated CVE-2026-73570, was addressed in version 10.1.20 released by the Zimbra security team on July 20.
Exploitation and Impact
This vulnerability enables unauthenticated attackers to execute arbitrary commands on affected systems through a command injection flaw in the SNMP monitoring component when SNMP notifications are enabled. The vulnerability arises from insufficient input validation during SNMP notification processing, allowing adversaries to craft malicious SMTP requests that trigger arbitrary operating system command execution under the Zimbra user context.
Exposed Servers and Monitoring
CERT Polska’s Warning
Shadowserver, an internet security monitoring organization, has identified over 12,100 Zimbra servers exposed online, with significant concentrations in Europe (4,382) and Asia (4,492). However, the data does not clarify whether these servers are honeypots or have been patched against the flaw. CERT Polska confirmed that threat actors are leveraging CVE-2026-73570 in active attacks.
Indicators of Compromise
The team advised administrators to scrutinize system logs for anomalies, including unexpected restarts of the Zimbra service and file creation activities in critical directories such as /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/ by the zimbra user within the past 30 days.
Historical Exploitation
Historical exploitation of Zimbra vulnerabilities highlights the platform’s attractiveness to cybercriminals. In February 2023, Russian-linked cyber espionage groups, including Winter Vivern, exploited a reflected XSS vulnerability to compromise Zimbra webmail portals, targeting NATO-aligned entities. In October 2024, US and UK cybersecurity agencies attributed attacks on Zimbra servers to APT29 (Midnight Blizzard), which exploited prior security flaws to steal account credentials. More recently, in March, researchers from Seqrite Labs documented APT28 (linked to Russia’s military intelligence) exploiting a stored XSS vulnerability in attacks against Ukrainian government ZCS servers.
2026 Report and Undetected Threats
A 2026 report analyzing 338 million security simulations revealed that 37% of malicious actions by adversaries with valid credentials go undetected. This underscores the importance of robust defense mechanisms and proactive monitoring.
Call to Action
Organizations using Zimbra Collaboration Suite are urged to apply the latest patches immediately and review their infrastructure for signs of compromise. The ongoing exploitation of Zimbra vulnerabilities emphasizes the need for continuous vigilance against emerging threats.
