• News/
  • bleepingcomputer-20260820094654

Critical Zimbra RCE flaw now actively exploited in attacks

BleepingComputer
·
Sergiu Gatlan
·
Published Aug 20, 2026
·
Updated

CERT Polska, the Polish Computer Emergency Response Team (CERT), warned that attackers have begun exploiting a critical vulnerability in Zimbra Collaboration Suite (ZCS). ZCS is a popular email and collaboration software suite used by hundreds of millions of people and organizations worldwide, including thousands of businesses and hundreds of government agencies. The Zimbra security team released version 10.1.20 on July 20 to patch the vulnerability (tracked as CVE-2026-73570), which allows unauthenticated attackers to gain remote code execution by exploiting a command injection weakness in the SNMP monitoring component when SNMP notifications are enabled. "Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user," it explained. Internet security watchdog Shadowserver now tracks over 12,100 Zimbra servers exposed online, most of them in Europe (4,382) and Asia (4,492). However, there is no information on how many of them are honeypots or have already been patched against the CVE-2026-73570 security flaw. On Monday, the Polish CERT team reported that threat actors are now exploiting CVE-2026-73570 in attacks. "The CERT Polska team reports on an actively used OS Command Injection vulnerability in the Zimbra Collaboration Suite," it warned. CERT Polska also asked admins to check their logs for sus...

Read full article

Affected Software

2 affected components
Zimbra Collaboration Suite=10.1.20
Zimbra Collaboration Suite

Frequently Asked Questions

1

Which Zimbra deployments are vulnerable to CVE-2026-73570?

The flaw affects Zimbra Collaboration Suite deployments where SNMP notifications are enabled. It is a command injection weakness in the SNMP monitoring component.

2

How can CVE-2026-73570 be exploited?

An unauthenticated attacker can send specially crafted SMTP requests during SNMP notification processing. Improper sanitization of untrusted input may allow arbitrary operating-system commands to run as the Zimbra user.

3

What action should Zimbra administrators take?

Administrators should update to Zimbra version 10.1.20, which was released on July 20 to patch CVE-2026-73570. CERT Polska has warned that attackers are actively exploiting the vulnerability.

4

How many potentially exposed Zimbra servers are tracked online?

Shadowserver tracks more than 12,100 internet-exposed Zimbra servers, with 4,382 in Europe and 4,492 in Asia. The article notes that it is unknown how many are honeypots or have already been patched.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203