Zimbra SNMP Vulnerability CVE-2026-73570 Actively Exploited for RCE
A critical command injection vulnerability in Zimbra Collaboration Suite (ZCS) is now being actively exploited in the wild, according to CERT Polska. Tracked as CVE-2026-73570 with a CVSS score of 8.9, the flaw resides in ZCS versions prior to 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Improper sanitization of untrusted input during SNMP notification processing allows unauthenticated attackers to send specially crafted SMTP requests that execute arbitrary operating system commands as the Zimbra user, effectively enabling remote code execution without credentials. Organizations running vulnerable Zimbra instances should patch to version 10.1.20 immediately. Administrators can audit exposure by scanning network ports used by Zimbra with our port scanner to confirm SNMP and SMTP services are properly segmented from the public internet.
CERT Polska warned this week that attackers are weaponizing the flaw against unpatched deployments. The agency urged defenders to inspect /var/log/zimbra.log for suspicious Zimbra service restarts and to review /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/ for files created within the last 30 days. Because Zimbra servers often hold sensitive corporate email, security teams should also run an email breach checker against administrator accounts to identify potential credential compromise that could compound the impact of exploitation. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-73570 to its Known Exploited Vulnerabilities (KEV) catalog on August 21, 2026, mandating Federal Civilian Executive Branch (FCEB) agencies to apply fixes by August 24.
Zimbra mail servers have long been a favored target for advanced persistent threat actors. Last month, U.S. authorities disclosed that Russia-linked group Laundry Bear — also tracked as CL-STA-1114, TA488, UNK_PitStop, and Void Blizzard — has been targeting Zimbra deployments belonging to Western government and commercial organizations since at least July 2025. That campaign weaponized CVE-2025-66376, a stored cross-site scripting bug in Zimbra's Classic UI, to deliver a JavaScript payload dubbed ZimReaper that harvested email communications and other sensitive data. Given the ongoing targeting, defenders should ensure administrative access is hardened with strong, unique credentials verified through a password checker.