Attackers Actively Exploit Critical Zimbra RCE Flaw in Email Servers
Attackers are now actively exploiting a critical remote code execution vulnerability in Zimbra Collaboration Suite, according to a warning from CERT Polska. The flaw, tracked as CVE-2026-73570, stems from improper sanitization of untrusted input in the SNMP monitoring component, which is triggered when SNMP notifications are enabled. An unauthenticated attacker can send specially crafted SMTP requests that execute arbitrary operating system commands as the Zimbra user.
Zimbra released version 10.1.20 on July 20 to patch the vulnerability, but many servers remain exposed. Shadowserver currently tracks more than 12,100 internet-facing Zimbra servers, with the majority located in Europe (4,382) and Asia (4,492). It remains unclear how many of these servers are honeypots or have already applied the security patch.
CERT Polska urges administrators to review their logs for suspicious activity, including the Zimbra service restarting on its own and files created by the zimbra user in the /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/ folders over the past 30 days. Zimbra flaws have long been prime targets for cyber spies, with the Winter Vivern group exploiting a Zimbra XSS flaw in 2023 and Russian-linked APT29 hackers targeting vulnerable Zimbra servers to steal email credentials.