Critical Zimbra RCE flaw now actively exploited in attacks
A critical vulnerability in Zimbra Collaboration Suite (ZCS) is being actively exploited by attackers. The flaw, tracked as CVE-2026-73570, allows unauthenticated attackers to gain remote code execution by exploiting a command injection weakness in the SNMP monitoring com…
Intelligence analysis by Llama

A critical vulnerability in Zimbra Collaboration Suite (ZCS) is being actively exploited by attackers. The flaw, tracked as CVE-2026-73570, allows unauthenticated attackers to gain remote code execution by exploiting a command injection weakness in the SNMP monitoring component when SNMP notifications are enabled. Over 12,100 Zimbra servers are exposed online, with most in Europe and …
Imagine you have a special kind of email server that lots of people and organizations use. There's a big problem with this server that makes it easy for bad people to take control of it. This is called a vulnerability. The bad people can use this vulnerability to do bad things, like steal emails or take control of the server. It's like leaving a door unlocked, and someone can just walk in and take whatever they want.
Analysis
Zimbra Collaboration Suite Vulnerability Overview
The Zimbra Collaboration Suite (ZCS) is a popular email and collaboration software suite used by hundreds of millions of people and organizations worldwide. Recently, a critical vulnerability was discovered in ZCS, tracked as CVE-2026-73570. This vulnerability allows unauthenticated attackers to gain remote code execution by exploiting a command injection weakness in the SNMP monitoring component when SNMP notifications are enabled.
The CERT Polska team reported that threat actors are now exploiting CVE-2026-73570 in attacks. They warned admins to check their logs for suspicious activity, such as the Zimbra service restarting on its own, and for files created in the /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/ folders by user zimbra over the last 30 days.
Zimbra flaws are frequently targeted in the wild and have been used to breach many vulnerable email servers in recent years. For instance, Russian Winter Vivern cyber spies used a reflected XSS exploit in February 2023 to steal emails belonging to NATO-aligned individuals and organizations from Zimbra webmail portals. In October 2024, US and UK cyber agencies warned that APT29 hackers (tracked as Midnight Blizzard and Cozy Bear and linked to Russia's Foreign Intelligence Service) were targeting vulnerable Zimbra servers by exploiting a security issue previously abused to steal email account credentials. More recently, in March, Seqrite Labs researchers also revealed that APT28 hackers (a state-backed threat group linked to Russia's military intelligence service) were exploiting a stored cross-site scripting (XSS) vulnerability in attacks targeting Ukrainian government ZCS servers.
The fact that over 12,100 Zimbra servers are exposed online, with most in Europe and Asia, makes this vulnerability a significant threat. It is essential for admins to patch their Zimbra servers against the CVE-2026-73570 security flaw as soon as possible to prevent potential security breaches.
Key points
- A critical vulnerability in Zimbra Collaboration Suite (ZCS) is being actively exploited by attackers.
- The flaw, tracked as CVE-2026-73570, allows unauthenticated attackers to gain remote code execution by exploiting a command injection weakness in the SNMP monitoring component when SNMP notifications are enabled.
- Over 12,100 Zimbra servers are exposed online, with most in Europe and Asia.
- Admins are warned to check their logs for suspicious activity and patch their Zimbra servers against the CVE-2026-73570 security flaw as soon as possible.
If admins patch their Zimbra servers against the CVE-2026-73570 security flaw, they can prevent potential security breaches. This will help keep their email servers and data safe from bad actors.
If admins don't patch their Zimbra servers against the CVE-2026-73570 security flaw, they risk being exploited by bad actors. This can lead to significant security breaches, including email account credentials being stolen or the server being taken over.



