Zimbra CVE-2026-73570 Exploited in Active Attacks Targeting Email Servers
Poland's CERT Polska has confirmed active in-the-wild exploitation of a recently patched vulnerability in the Zimbra Collaboration Suite, tracked as CVE-2026-73570. The high-severity flaw was addressed by Zimbra developers with the release of version 10.1.20 on July 20, but attackers appear to be moving quickly against unpatched deployments. The bug is triggered when the optional 'zimbra-snmp' package is installed and SNMP notifications are enabled, allowing unauthenticated attackers to execute arbitrary OS commands as the Zimbra user.
CERT Polska disclosed this week that it has observed exploitation attempts but withheld technical details about the campaign, sharing only indicators of compromise (IoCs). The threat actor's identity and motivation remain unknown, though successful exploitation grants full control over a targeted Zimbra server. From that foothold, attackers can establish persistence, access email accounts, harvest credentials, and pivot laterally across the network. Organizations running Zimbra should verify their build version immediately and audit any Zimbra deployments that may have exposed SNMP services; a quick port scanner check can confirm whether SNMP ports (161/UDP) are unnecessarily reachable from the internet.
CISA's Known Exploited Vulnerabilities (KEV) catalog currently lists 18 Zimbra Collaboration Suite flaws, including four added in 2025, though CVE-2026-73570 has not yet been catalogued. Past Zimbra exploitation has frequently been attributed to Russian and Chinese state-sponsored groups targeting military and diplomatic intelligence, as well as financially motivated cybercriminals. Given the credential-harvesting potential of any successful compromise, administrators should also review account exposure using an email breach checker and force password resets for any accounts that may have been accessed during the window of exposure. Operators who rely on Zimbra for sensitive communications should additionally validate TLS configurations via an SSL/TLS checker to ensure encrypted channels have not been downgraded or intercepted.