The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies to patch an actively exploited vulnerability in Zimbra Collaboration Suite (ZCS) within three days. The vulnerability, tracked as CVE-2026-73570, was patched by the Zimbra security team in version 10.1.20, released on July 20.
Remote Code Execution Vulnerability
Successful exploitation of the vulnerability allows unauthenticated attackers to gain remote code execution by exploiting a command injection weakness in the SNMP monitoring component when SNMP notifications are enabled on the targeted system. According to the Zimbra security team, due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
CISA's Warning and CERT Polska's Alert
CISA's warning comes after CERT Polska, the Polish Computer Emergency Response Team (CERT), first flagged the vulnerability as targeted in the wild last Monday. While threat security watchdog Shadowserver tracks more than 12,000 Zimbra servers exposed on the Internet, there is no information on how many are honeypots or have already been secured against attacks exploiting the CVE-2026-73570 flaw.
On Monday, Shadowserver also said it has found over 270 compromised Zimbra Collaboration Suite instances while looking for CVE-2026-73570 exploitation artifacts. Zimbra Collaboration Suite servers exposed online are a significant concern, as the suite is a popular email and collaboration platform used by hundreds of millions of organizations and people worldwide, including hundreds of government agencies and thousands of businesses.
Potential Impact and Previous Attacks
Zimbra security issues are commonly targeted in the wild and have been used to steal sensitive data from vulnerable email servers in recent years. Most recently, Seqrite Labs researchers revealed in March that APT28 (a state-sponsored threat group linked to Russia's military intelligence service) was exploiting a stored cross-site scripting (XSS) vulnerability in attacks targeting Ukrainian government ZCS servers.
In October 2024, U.S. and UK cyber agencies warned that APT29 hackers (tracked as Midnight Blizzard and Cozy Bear) linked to Russia's Foreign Intelligence Service were targeting Zimbra servers using a flaw previously exploited to steal email account credentials. Russian Winter Vivern cyber spies have also abused a reflected Cross-Site Scripting (XSS) vulnerability to steal emails belonging to NATO-aligned individuals and organizations via Zimbra webmail portals.
Prevention and Recommendations
Once attackers have valid credentials, only 37% of their actions are blocked, according to The Blue Report 2026, which measures defenses technique by technique across 338 million simulations run in customer production environments. The report highlights the importance of preventing initial access and having robust defenses in place to prevent attackers from using valid credentials to carry out further malicious activities.
CISA has ordered U.S. Federal Civilian Executive Branch (FCEB) agencies to secure their systems within three days, by August 24. The Polish CERT team has also asked security teams to check logs for suspicious activity, such as the Zimbra service restarting unexpectedly, and for files created in the /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/ folders by user zimbra over the last 30 days.
Source: BleepingComputer