A critical Zimbra RCE flaw is now being actively exploited, prompting administrators to patch vulnerable email servers and review their systems for signs of compromise. The issue affects Zimbra Collaboration Suite installations that use SNMP notifications.
Tracked as CVE-2026-73570, the vulnerability allows an unauthenticated attacker to execute operating-system commands as the Zimbra user. Attackers can trigger the flaw through specially crafted SMTP requests, potentially giving them a route into a targeted email environment.
Critical Zimbra flaw allows remote code execution
Zimbra released version 10.1.20 on July 20, 2026, to fix CVE-2026-73570. The security issue stems from improper handling of untrusted input during SNMP notification processing.
When SNMP notifications are enabled, an attacker can exploit the command injection weakness without logging in first. That lowers the barrier for attacks and makes exposed, unpatched servers an attractive target.
The Zimbra RCE flaw carries particular weight because email platforms often hold sensitive correspondence, user data and internal business information. A successful compromise could also give attackers a foothold for wider activity inside an organisation’s network.
Thousands of Zimbra servers remain exposed online
More than 12,100 Zimbra servers are visible on the public internet, according to Shadowserver tracking. Europe and Asia account for the largest shares, with thousands of exposed systems in each region.
Public exposure does not automatically mean a server is vulnerable. Some systems may be honeypots, while others may already run the patched version. However, the total still highlights the potential attack surface available to threat actors.
Administrators should not assume that a public-facing Zimbra instance is safe simply because it has not shown obvious issues. Attackers commonly scan for exposed servers after security researchers and vendors disclose serious vulnerabilities.
CERT Polska confirms active exploitation
CERT Polska warned on August 17 that attackers had begun exploiting the Zimbra RCE flaw in real-world attacks. The agency urged administrators to inspect their Zimbra environments and look for suspicious behaviour.
One warning sign is an unexpected restart of the Zimbra service. Administrators should also review files created by the zimbra user during the previous 30 days, especially in the following directories:
/opt/zimbra/jetty/webapps//opt/zimbra/jetty_base/webapps//tmp/
Unexpected files in these locations may indicate that an attacker used the vulnerability to deploy payloads or establish persistence. Security teams should preserve relevant logs and investigate unusual activity before deleting potential evidence.
Zimbra servers remain a frequent target
Threat groups have repeatedly targeted Zimbra vulnerabilities in recent years. In 2023, the Russian-linked Winter Vivern group used a Zimbra cross-site scripting issue to steal emails from organisations and individuals connected to NATO countries.
US and UK agencies also warned in 2024 that APT29, also known as Midnight Blizzard or Cozy Bear, targeted vulnerable Zimbra servers. More recently, researchers linked APT28 activity to attacks on Ukrainian government Zimbra servers through another stored cross-site scripting flaw.
These incidents show why Zimbra administrators need to treat critical patches as urgent maintenance, especially when attackers begin exploiting a bug publicly.
Conclusion
The Zimbra RCE flaw CVE-2026-73570 now poses an immediate risk to unpatched installations. Organisations should update to Zimbra version 10.1.20 or later, check whether SNMP notifications are enabled and investigate their servers for the indicators flagged by CERT Polska.


0 responses to “Zimbra RCE Flaw Actively Exploited in Attacks”