Hackers Target Zimbra Servers in Active Exploitation Campaign
CVE-2026-73570 is a high-severity, unauthenticated remote code execution vulnerability in Zimbra Collaboration Suite affecting installations with the optional zimbra-snmp package and SNMP notifications enabled The vulnerability was patched in Zimbra version 10.1.20, released on July 20, but is already being actively exploited in the wild according to Poland's CERT Polska Attackers can execute arbitrary OS commands as the Zimbra user without any authentication, potentially gaining full server con
Analysis
TL;DR
- CVE-2026-73570 is a high-severity, unauthenticated remote code execution vulnerability in Zimbra Collaboration Suite affecting installations with the optional zimbra-snmp package and SNMP notifications enabled
- The vulnerability was patched in Zimbra version 10.1.20, released on July 20, but is already being actively exploited in the wild according to Poland's CERT Polska
- Attackers can execute arbitrary OS commands as the Zimbra user without any authentication, potentially gaining full server control, establishing persistence, harvesting credentials, and moving laterally
- CISA's Known Exploited Vulnerabilities (KEV) catalog currently lists 18 Zimbra Collaboration Suite vulnerabilities, with four added this year, but CVE-2026-73570 has not yet been added
- Zimbra exploitation has historically been linked to both Russian and Chinese state-sponsored actors targeting military and diplomatic intelligence, as well as opportunistic cybercriminals
Why It Matters
This vulnerability is critical for any organization running Zimbra Collaboration Suite with SNMP enabled, as it allows unauthenticated attackers to achieve full remote code execution — a direct path to complete server compromise. The active exploitation in the wild, combined with Zimbra's history as a target for both nation-state and criminal actors, makes immediate patching and SNMP remediation essential for enterprise email infrastructure security.
Technical Details
- Vulnerability: CVE-2026-73570, a high-severity unauthenticated RCE flaw in Zimbra Collaboration Suite
- Attack vector: Exploitable when the optional
zimbra-snmppackage is installed and SNMP notifications are enabled; no authentication required - Impact: Arbitrary OS command execution as the Zimbra user, enabling full server compromise, persistence, credential harvesting, and lateral movement
- Patch: Zimbra version 10.1.20, released July 20
- Context: CISA KEV catalog includes 18 prior Zimbra vulnerabilities (4 added this year); CVE-2026-73570 is not yet listed
Industry Insight
- Organizations running Zimbra should immediately disable the
zimbra-snmppackage or SNMP notifications if patching cannot be applied instantly, and prioritize upgrading to version 10.1.20 - Given the pattern of Zimbra exploitation by both state-sponsored and criminal actors, enterprises should assume active compromise is possible and conduct thorough IoC-based hunting across their environments
- This incident reinforces the importance of CISA KEV catalog monitoring and rapid patching workflows for enterprise collaboration platforms, especially those with unauthenticated RCE potential
Disclaimer: The above content is generated by AI and is for reference only.