Active Exploitation of Critical Zimbra Flaw Puts Thousands at Risk

Poland’s national cybersecurity agency has confirmed that attackers are actively exploiting a critical unauthenticated remote code execution flaw in Zimbra Collaboration Suite. Tracked as CVE-2026-73570, the vulnerability was patched on July 20, but threat actors have already weaponized it—leaving thousands of servers vulnerable if left unpatched.
A narrow patch window, a broad attack surface
CVE-2026-73570 stems from insufficient input sanitization in the SNMP monitoring component of Zimbra. It allows attackers to execute arbitrary shell commands with the privileges of the zimbra user, but only when the optional zimbra-snmp package is installed and SNMP trap notifications are enabled. Even then, the swatchdog service—enabled by default—processes those notifications, creating a viable attack path. Zimbra released version 10.1.20 to address the issue, but the 28-day gap between patch and active exploitation shows how quickly attackers move.
How to spot an attack in progress
CERT Polska has published indicators of compromise and recommends checking Zimbra logs for telltale signs. Administrators should scan /var/log/zimbra.log for entries where service status changes from stopped to running and back—suggesting a malicious payload being toggled on and off. They should also look for files created by the zimbra user in the last 30 days within /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, or /tmp/, which could indicate persistent web shells.
A landscape of exposed systems
Shadowserver currently tracks over 12,100 Zimbra servers reachable from the internet, with Europe and Asia hosting the majority. While the figure includes honeypots and patched systems, the sheer volume underscores the scale of potential exposure.
Why it matters
This isn’t just another vulnerability—it’s a race against time for organizations running Zimbra. The active exploitation confirms that patching alone isn’t enough; defenders must hunt for signs of compromise and remove unauthorized access. With thousands of internet-facing servers still potentially at risk, the window for preventing breaches is closing fast.
Source: Security Affairs. AI-assisted editorial synthesis — TechnoExpress.

