A recently patched Zimbra Collaboration vulnerability is being exploited in the wild, according to Poland’s CERT Polska.
The security hole, tracked as CVE-2026-73570, was addressed by the developers of the enterprise email server and collaborative software suite with the release of version 10.1.20 on July 20. The high-severity flaw exists when the optional ‘zimbra-snmp’ package is installed and SNMP notifications are enabled.
An attacker can exploit this vulnerability without authentication to execute arbitrary OS commands as the Zimbra user. The Polish CERT reported observing attacks this week but did not provide specific details about the active exploitation campaign. However, they did share some indicators of compromise (IoCs).
The identity and motivation of the threat actor behind these attacks remain unclear. Exploiting this vulnerability could allow attackers to gain full control of a targeted Zimbra server, enabling them to establish persistence, access email accounts, harvest credentials, and move laterally to other systems.
CISA’s KEV catalog currently includes 18 Zimbra Collaboration Suite vulnerabilities, with four added this year. Notably, CVE-2026-73570 has yet to be included in the catalog.
Historically, the exploitation of Zimbra vulnerabilities has been linked to Russian and Chinese state-sponsored hackers targeting military and diplomatic intelligence, as well as opportunistic cybercriminals seeking financial gain. For further details, see the report by SecurityWeek.
Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.


