CERT Polska, the Polish Computer Emergency Response Team (CERT), warned that attackers have begun exploiting a critical vulnerability in Zimbra Collaboration Suite (ZCS). ZCS is a popular email and collaboration software suite used by hundreds of millions of people and organizations worldwide, including thousands of businesses and hundreds of government agencies. The Zimbra security team released version 10.1.20 on July 20 to patch the vulnerability (tracked as CVE-2026-73570), which allows unauthenticated attackers to gain remote code execution by exploiting a command injection weakness in the SNMP monitoring component when SNMP notifications are enabled. "Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user," it explained. Internet security watchdog Shadowserver now tracks over 12,100 Zimbra servers exposed online, most of them in Europe (4,382) and Asia (4,492). However, there is no information on how many of them are honeypots or have already been patched against the CVE-2026-73570 security flaw. On Monday, the Polish CERT team reported that threat actors are now exploiting CVE-2026-73570 in attacks. "The CERT Polska team reports on an actively used OS Command Injection vulnerability in the Zimbra Collaboration Suite," it warned. CERT Polska also asked admins to check their logs for sus...
Critical Zimbra RCE flaw now actively exploited in attacks
Affected Software
Frequently Asked Questions
Which Zimbra deployments are vulnerable to CVE-2026-73570?
The flaw affects Zimbra Collaboration Suite deployments where SNMP notifications are enabled. It is a command injection weakness in the SNMP monitoring component.
How can CVE-2026-73570 be exploited?
An unauthenticated attacker can send specially crafted SMTP requests during SNMP notification processing. Improper sanitization of untrusted input may allow arbitrary operating-system commands to run as the Zimbra user.
What action should Zimbra administrators take?
Administrators should update to Zimbra version 10.1.20, which was released on July 20 to patch CVE-2026-73570. CERT Polska has warned that attackers are actively exploiting the vulnerability.
How many potentially exposed Zimbra servers are tracked online?
Shadowserver tracks more than 12,100 internet-exposed Zimbra servers, with 4,382 in Europe and 4,492 in Asia. The article notes that it is unknown how many are honeypots or have already been patched.