HackMyIP
← Back to News
2026-08-20 SecurityWeek

Zimbra CVE-2026-73570 Exploited in Active Attacks Targeting Email Servers

VulnerabilityThreat Intel

Poland's CERT Polska has confirmed active in-the-wild exploitation of a recently patched vulnerability in the Zimbra Collaboration Suite, tracked as CVE-2026-73570. The high-severity flaw was addressed by Zimbra developers with the release of version 10.1.20 on July 20, but attackers appear to be moving quickly against unpatched deployments. The bug is triggered when the optional 'zimbra-snmp' package is installed and SNMP notifications are enabled, allowing unauthenticated attackers to execute arbitrary OS commands as the Zimbra user.

CERT Polska disclosed this week that it has observed exploitation attempts but withheld technical details about the campaign, sharing only indicators of compromise (IoCs). The threat actor's identity and motivation remain unknown, though successful exploitation grants full control over a targeted Zimbra server. From that foothold, attackers can establish persistence, access email accounts, harvest credentials, and pivot laterally across the network. Organizations running Zimbra should verify their build version immediately and audit any Zimbra deployments that may have exposed SNMP services; a quick port scanner check can confirm whether SNMP ports (161/UDP) are unnecessarily reachable from the internet.

CISA's Known Exploited Vulnerabilities (KEV) catalog currently lists 18 Zimbra Collaboration Suite flaws, including four added in 2025, though CVE-2026-73570 has not yet been catalogued. Past Zimbra exploitation has frequently been attributed to Russian and Chinese state-sponsored groups targeting military and diplomatic intelligence, as well as financially motivated cybercriminals. Given the credential-harvesting potential of any successful compromise, administrators should also review account exposure using an email breach checker and force password resets for any accounts that may have been accessed during the window of exposure. Operators who rely on Zimbra for sensitive communications should additionally validate TLS configurations via an SSL/TLS checker to ensure encrypted channels have not been downgraded or intercepted.

Source: SecurityWeek →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →