ProBackend
active vulnerability exploitation
1 day ago5 min read

CERT Polska Warns of Active Zimbra RCE Exploitation as Attackers Target CVE-2026-73570

Polish Computer Emergency Response Team CERT Polska has warned that threat actors are actively exploiting a critical remote code execution vulnerability (CVE-2026-73570) in Zimbra Collaboration Suite, affecting SNMP monitoring components with enabled notifications.

CERT Polska Warns of Active Zimbra RCE Exploitation

CERT Polska, the Polish Computer Emergency Response Team (CERT), warned that attackers have begun exploiting a critical vulnerability in Zimbra Collaboration Suite (ZCS). The Polish CERT team reports on an actively used OS Command Injection vulnerability in the Zimbra Collaboration Suite. ZCS is a popular email and collaboration software suite used by hundreds of millions of people and organizations worldwide, including thousands of businesses and hundreds of government agencies.

The Zimbra security team released version 10.1.20 on July 20 to patch the vulnerability (tracked as CVE-2026-73570), which allows unauthenticated attackers to gain remote code execution by exploiting a command injection weakness in the SNMP monitoring component when SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

Internet security watchdog Shadowserver now tracks over 12,100 Zimbra servers exposed online, most of them in Europe (4,382) and Asia (4,492). However, there is no information on how many of them are honeypots or have already been patched against the CVE-2026-73570 security flaw.

On Monday, the Polish CERT team reported that threat actors are now exploiting CVE-2026-73570 in attacks. The CERT Polska team reports on an actively used OS Command Injection vulnerability in the Zimbra Collaboration Suite, it warned. CERT Polska also asked admins to check their logs for suspicious activity, such as the Zimbra service restarting on its own, and for files created in the /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/ folders by user zimbra over the last 30 days.

Zimbra flaws are frequently targeted in the wild and have been used to breach many vulnerable email servers in recent years. For instance, Russian Winter Vivern cyber spies used a reflected XSS exploit in February 2023 to steal emails belonging to NATO-aligned individuals and organizations from Zimbra webmail portals. In October 2024, US and UK cyber agencies warned that APT29 hackers (tracked as Midnight Blizzard and Cozy Bear and linked to Russia's Foreign Intelligence Service) were targeting vulnerable Zimbra servers by exploiting a security issue previously abused to steal email account credentials. More recently, in March, Seqrite Labs researchers also revealed that APT28 hackers (a state-backed threat group linked to Russia's military intelligence service) were exploiting a stored cross-site scripting (XSS) vulnerability in attacks targeting Ukrainian government ZCS servers.

Once attackers have valid credentials, only 37% of their actions are blocked. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

CERT Polska urged administrators to take immediate protective measures. The team specifically recommended checking logs for suspicious activity such as the Zimbra service restarting on its own and files created in the /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/ folders by user zimbra over the last 30 days. Administrators should verify that their Zimbra Collaboration Suite instances are running the patched version 10.1.20 or later. Systems still on older versions remain at risk of remote code execution through the SNMP notification vector.

The vulnerability's severity is amplified by the wide exposure of Zimbra servers globally. Shadowserver's count of 12,100+ exposed instances means a significant attack surface, particularly in Europe and Asia where the majority of vulnerable systems reside. The lack of visibility into which of these servers have been patched creates additional risk for organizations that may assume their systems are protected.

Historical Context of Zimbra Exploits

Zimbra security flaws have been repeatedly exploited in campaigns spanning several years. In February 2023, Russian Winter Vivern cyber spies used a reflected XSS exploit to steal emails from NATO-aligned individuals and organizations through Zimbra webmail portals. The intrusion demonstrated how vulnerabilities in email infrastructure can be weaponized for intelligence gathering against geopolitical allies.

October 2024 saw warnings from US and UK cyber agencies about APT29 hackers, tracked as Midnight Blizzard and Cozy Bear and linked to Russia's Foreign Intelligence Service, targeting vulnerable Zimbra servers. The group exploited a security issue previously abused to steal email account credentials, indicating a pattern of leveraging known weaknesses for credential harvesting operations.

More recently, March 2026 research from Seqrite Labs revealed that APT28 hackers, a state-backed threat group linked to Russia's military intelligence service, were exploiting a stored cross-site scripting (XSS) vulnerability in attacks targeting Ukrainian government ZCS servers. This sequence of attacks spanning different threat actors and vectors illustrates the sustained interest in Zimbra platforms by various state-affiliated actors.

Broader Security Implications

The CVE-2026-73570 case adds to a growing pattern of email and collaboration platforms being targeted for initial access in broader campaigns. Once attackers establish footholds through such vulnerabilities, the downstream impact can be substantial. The Blue Report 2026 findings underscore that prevention rates can be misleading — once attackers have valid credentials, defense effectiveness drops sharply, with only 37% of actions blocked in measured environments.

Organizations relying on Zimbra Collaboration Suite should prioritize patching to the latest release, review SNMP notification configurations, and enhance monitoring for the specific log indicators called out by CERT Polska. The convergence of active exploitation, wide server exposure, and historical weaponization by multiple threat actor groups makes this a timely and significant security concern.

Source: CERT Polska warning via BleepingComputer report on critical Zimbra RCE flaw now actively exploited in attacks, August 20, 2026.

cert polska warns of active zimbra rce exploitation

More blogs