
CERT Polska, the Polish Laptop Emergency Response Crew (CERT), warned that attackers have begun exploiting a crucial vulnerability in Zimbra Collaboration Suite (ZCS).
ZCS is a well-liked electronic mail and collaboration software program suite utilized by lots of of tens of millions of individuals and organizations worldwide, together with hundreds of companies and lots of of presidency companies.
The Zimbra safety workforce released version 10.1.20 on July 20 to patch the vulnerability (tracked as CVE-2026-73570), which permits unauthenticated attackers to realize distant code execution by exploiting a command injection weak spot within the SNMP monitoring part when SNMP notifications are enabled.
“Attributable to improper sanitization of untrusted enter throughout SNMP notification processing, an unauthenticated attacker can ship specifically crafted SMTP requests which will lead to execution of arbitrary working system instructions because the Zimbra person,” it defined.
Web safety watchdog Shadowserver now tracks over 12,100 Zimbra servers uncovered on-line, most of them in Europe (4,382) and Asia (4,492).
Nevertheless, there isn’t a info on what number of of them are honeypots or have already been patched in opposition to the CVE-2026-73570 safety flaw.

Flagged as actively exploited
On Monday, the Polish CERT workforce reported that menace actors are actually exploiting CVE-2026-73570 in assaults.
“The CERT Polska workforce experiences on an actively used OS Command Injection vulnerability within the Zimbra Collaboration Suite,” it warned.
CERT Polska additionally requested admins to test their logs for suspicious exercise, such because the Zimbra service restarting by itself, and for recordsdata created within the /choose/zimbra/jetty/webapps/, /choose/zimbra/jetty_base/webapps/, and /tmp/ folders by person zimbra over the past 30 days.
Zimbra flaws are continuously focused within the wild and have been used to breach many weak electronic mail servers in recent times.
For example, Russian Winter Vivern cyber spies used a mirrored XSS exploit in February 2023 to steal emails belonging to NATO-aligned people and organizations from Zimbra webmail portals.
In October 2024, US and UK cyber companies warned that APT29 hackers (tracked as Midnight Blizzard and Cozy Bear and linked to Russia’s Overseas Intelligence Service) had been targeting vulnerable Zimbra servers by exploiting a safety problem beforehand abused to steal email account credentials.
Extra just lately, in March, Seqrite Labs researchers additionally revealed that APT28 hackers (a state-backed menace group linked to Russia’s army intelligence service) had been exploiting a saved cross-site scripting (XSS) vulnerability in attacks targeting Ukrainian government ZCS servers.
General prevention scores can disguise what occurs after preliminary entry. As soon as attackers are utilizing legitimate credentials, prevention drops sharply.
The Blue Report 2026 measures defenses approach by approach throughout 338 million simulations run in buyer manufacturing environments.

