All incidents

Zimbra Collaboration RCE vulnerability (CVE-2026-73570) exploited in the wild

malwareopenAug 20, 2026 — Aug 20, 2026
Zimbra CVE-2026-73570 bug lets attackers run OS commands

A high‑severity flaw in Zimbra Collaboration Suite is being used in the wild to run arbitrary operating system commands on affected servers, according to an alert from CERT Polska. The vulnerability, tracked as CVE‑2026-73570, impacts installations that have the zimbra‑snmp component installed and can be exploited without authentication. A patch was issued in version 10.1.20 released on 20 July 2026. Systems running older releases remain exposed.

The flaw carries a CVSS score of 8.9, marking it as high risk. It resides in the way the zimbra‑snmp package processes incoming SNMP notifications, allowing a remote attacker to inject shell commands that execute with the privileges of the zimbra user. No prior credentials are needed; a specially crafted SNMP trap is sufficient to trigger the issue. Successful exploitation grants the attacker full command line access to the underlying host.

Versions of Zimbra Collaboration Suite earlier than 10.1.20 are vulnerable, regardless of the underlying operating system. Once inside, threat actors have been observed installing web shells, dumping mailbox data and harvesting credentials stored on the server. The attack chain does not require any interaction from legitimate users, making it particularly stealthy. Log entries may show unexpected SNMP requests followed by unknown process spawns under the zimbra account.

CERT Polska first disclosed the activity on 20 August 2026, noting that exploitation attempts have been detected across multiple geographic regions. The identity of the operators behind the campaign remains unknown, although similar vulnerabilities in Zimbra have previously been linked to groups associated with Russian and Chinese state‑sponsored programmes. At present the flaw is not listed in the Known Exploited Vulnerabilities catalogue maintained by CISA.

Administrators should upgrade to Zimbra Collaboration Suite version 10.1.20 or later as a matter of priority, following the guidance published by the vendor and SecurityOnline. After updating, it is advisable to review authentication logs and audit files created by the zimbra user in directories such as /opt/zimbra/data/tmp for signs of compromise. Disabling the zimbra‑snmp service when it is not required can also reduce the attack surface while a patch is being applied.

If an immediate upgrade is not feasible, blocking UDP port 161 and TCP port 161 at the network perimeter will prevent unauthenticated SNMP traffic from reaching the server. Implementing network segmentation to isolate the Zimbra service from untrusted zones and enforcing multifactor authentication for administrative interfaces adds further defence. Regularly reviewing security advisories and maintaining offline backups ensure that recovery remains possible even if a breach occurs.

Intelligence briefing updated Aug 20, 2026

CVE-2026-73570 8.9
Root sourcemoje.cert.pl
Timeline Coverage

Swipe to explore timeline