securityaffairs.com 8/21/2026, 10:40:56 AM · external

CERT Polska warns of Zimbra RCE flaw CVE-2026-73570 after patch

CERT Polska warns of Zimbra RCE flaw CVE-2026-73570 after patch
Developing story incident 4 articles tracked
Zimbra Collaboration SNMP vulnerability (CVE-2026-73570) exploited in the wild
CyberSIXT Evidence Panel
Primary Source moje.cert.pl
CISA KEV Not in KEV
Patch Patch Status Unknown

CERT Polska has reported active exploitation of a critical vulnerability (CVE-2026-73570) in the Zimbra Collaboration Suite, which allows unauthenticated remote code execution (RCE). The flaw, confirmed as being exploited shortly after a patch was issued on July 20, 2026, specifically affects systems with enabled SNMP trap notifications and the swatchdog service, both of which are set by default.

Administrators are advised to check logs for signs of exploitation and verify file creation by the zimbra user in certain directories. With over 12,100 Zimbra servers potentially reachable online, the vulnerability presents a significant risk, particularly for organizations targeted by state-backed actors.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline