Zimbra Collaboration Under Active Exploitation: RCE Flaw Targeted In The Wild
A recently patched command injection vulnerability in **Zimbra Collaboration Suite (ZCS)**, tracked as **CVE-2026-73570**, is now actively being exploited. The flaw, which allows for unauthenticated remote code execution, specifically impacts instances with the optional `zimbra-snmp` package installed and SNMP notifications enabled. IT security professionals and privacy-conscious users are urged to apply the latest patches and scrutinize their systems for signs of compromise.

The Polish Computer Emergency Response Team (**CERT Polska**) has issued a critical alert regarding active exploitation of a command injection vulnerability in **Zimbra Collaboration (ZCS)**.
### The Vulnerability: CVE-2026-73570
The flaw, designated as **CVE-2026-73570** with a CVSS score of 8.9, enables remote code execution. According to the **NIST National Vulnerability Database (NVD)**, it affects **Zimbra Collaboration** versions prior to 10.1.20 when the optional `zimbra-snmp` package is installed and SNMP notifications are active.
Improper sanitization of untrusted input during SNMP notification processing allows an unauthenticated attacker to send specially crafted SMTP requests. These requests can lead to the execution of arbitrary operating system commands under the privileges of the Zimbra user.
**Zimbra** addressed this critical security issue last month with the release of version 10.1.20.
### Indicators of Compromise and Mitigation
**CERT Polska**'s bulletin this week highlights ongoing exploitation efforts. Organizations utilizing **Zimbra Collaboration** are strongly advised to check their systems for potential compromise.
Key indicators to look for include:
* Suspicious **Zimbra** service restarts in the `/var/log/zimbra.log` file.
* Newly created files within the last 30 days in the following directories:
* `/opt/zimbra/jetty/webapps/`
* `/opt/zimbra/jetty_base/webapps/`
* `/tmp/`
Immediate patching to **Zimbra Collaboration** version 10.1.20 or later is the primary mitigation strategy.
### A Recurring Target for Threat Actors
**Zimbra** vulnerabilities have historically been a favored target for various threat actors. Just last month, the U.S. government revealed details of a sophisticated phishing campaign attributed to a Russia-linked adversary known as **Laundry Bear** (also identified as **CL-STA-1114**, **TA488**, **UNK_PitStop**, and **Void Blizzard**).
This campaign, active since at least July 2025, specifically targeted **Zimbra** mail servers belonging to Western government and commercial organizations. It weaponized **CVE-2025-66376**, a stored cross-site scripting vulnerability in Zimbra's Classic UI, to deploy a malicious JavaScript payload dubbed **ZimReaper**. This payload was designed to harvest email communications and other sensitive data, underscoring the persistent threat landscape surrounding **Zimbra** installations.