Poland’s CERT Warns of Energetic Exploitation of Vital Zimbra Collaboration Suite Flaw

CERT Polska confirmed lively exploitation of CVE-2026-73570, a important unauthenticated RCE in Zimbra Collaboration Suite patched on July 20.
CERT Polska, Poland’s nationwide laptop emergency response crew, confirmed this week that menace actors are actively exploiting a important vulnerability in Zimbra Collaboration Suite tracked as CVE-2026-73570. The flaw permits unauthenticated distant code execution and was patched lower than a month in the past.
“The CERT Polska crew informs about an actively exploited OS Command Injection vulnerability in Zimbra Collaboration Suite.” reads the advisory printed by CERT Polska. “The vulnerability, recognized as CVE-2026-73570 , permits an unauthenticated attacker to execute arbitrary shell instructions with the privileges of the zimbra person . The vulnerability impacts situations which have the SNMP entice service enabled through the snmp_notify parameter and the swatchdog service working (enabled by default).”
The vulnerability impacts methods with SNMP entice notifications enabled and the swatchdog service working, which is enabled by default. The technical root trigger is a sanitization failure within the SNMP monitoring element.
Zimbra launched model 10.1.20 on 20 July 2026 to deal with the problem. The repair got here 28 days earlier than lively exploitation was confirmed, which isn’t a large window, however apparently large sufficient.
The assault floor solely exists when the elective zimbra-snmp bundle is put in and SNMP notifications are lively, however swatchdog, the service that processes these notifications, is working by default on most installations.
Beneath are suggestions by CERT Polska:
“Because of the ongoing marketing campaign exploiting this vulnerability, we advocate:
- verifying Zimbra logs /var/log/zimbra.log for the next entries:
Service standing change: modified from stopped to working
Service standing change: modified from working to stopped
- verification of information created by person zimbra within the final 30 days within the following directories:
/decide/zimbra/jetty/webapps/
/decide/zimbra/jetty_base/webapps/
/tmp/
In the event you uncover any indicators of potential exploitation of this vulnerability, please contact our crew instantly.”
The publicity numbers aren’t reassuring. Shadowserver currently tracks over 12,100 Zimbra servers reachable from the Web, break up roughly between Europe (4,382) and Asia (4,492). That determine doesn’t distinguish between patched and unpatched situations, or between manufacturing servers and honeypots, so the true assault floor is smaller, however no one is aware of by how a lot.
CERT Polska printed indicators of compromise alongside the advisory and gave directors particular locations to look. The crew recommends checking /var/log/zimbra.log for service standing change entries the place the payload transitions from stopped to working and again, which is the signature of a malicious command being executed as a service. Admins must also test whether or not any information have been created in /decide/zimbra/jetty/webapps/, /decide/zimbra/jetty_base/webapps/, or /tmp/ by the zimbra person within the final 30 days. Internet shells dropped into these directories would give persistent entry after the preliminary command injection.
CVE-2026-73570 isn’t but in CISA’s Recognized Exploited Vulnerabilities catalog, which at the moment lists 18 Zimbra Collaboration Suite entries, 4 of them added this yr. The absence doesn’t imply the menace is decrease; it means the catalog hasn’t caught up but.
Zimbra options have been focused by nation-state actors for years. Russian espionage group Winter Vivern exploited a mirrored XSS flaw in February 2023 to steal emails from NATO-aligned organizations by way of Zimbra webmail portals. In October 2024, US and UK companies warned that APT29, linked to Russia’s International Intelligence Service, was focusing on weak Zimbra servers through a credential-stealing flaw. Most lately, in March 2026, Seqrite Labs researchers documented APT28, tied to Russian navy intelligence, exploiting a saved XSS vulnerability in opposition to Ukrainian authorities Zimbra deployments.
Organizations in sectors focused by Russian or Chinese language state-backed teams ought to deal with unpatched Zimbra servers as a excessive precedence. CVE-2026-73570 is very dangerous as a result of attackers can exploit it with out authentication, the weak service is enabled by default, and plenty of Zimbra servers are uncovered on-line. These situations make the flaw a sexy goal for fast exploitation.
Comply with me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Zimbra Collaboration Suite)