Hackers are targeting Zimbra servers as part of an active exploitation campaign

Hackers are targeting Zimbra servers as part of an active exploitation campaign

According to Polish company CERT Polska, a recently patched vulnerability in Zimbra Collaboration is currently being exploited.

The vulnerability is tracked as CVE-2026-73570 and it was patched by the developers of the enterprise email server and collaborative software suite with the release of version 10.1.20 announced on July 20.

The high severity error exists when the optional zimbra-snmp package is installed and SNMP notifications are enabled.

An attacker could exploit the vulnerability without authentication to execute arbitrary operating system commands as a Zimbra user.

Poland’s CERT said there had been attacks this week, but did not share details about the active exploitation campaign. However, some were shared Indicators of Compromise (IoCs).

The threat actor behind these attacks and their motivation remain unclear. However, these vulnerabilities could allow threat actors to gain complete control of a targeted Zimbra server. The hackers can then build persistence, access email accounts, collect credentials, and move laterally into other systems.

Advertising. Scroll to continue reading.

CISA’s KEV catalog currently includes 18 vulnerabilities in the Zimbra Collaboration Suite, including four that were added this year. CVE-2026-73570 has yet to be added to the catalog.

Exploitation of Zimbra vulnerabilities has often been linked to state-sponsored Russian and Chinese hackers targeting military and diplomatic intelligence agencies, as well as opportunistic cybercriminals seeking financial gain.

Related: MLflow vulnerability exploited for cloud credential theft

Related: Critical GitLab flaw was exploited shortly after disclosure

Related: Exploitation of critical authentication bypass expected in Citrix NetScaler

Leave a Reply

Your email address will not be published. Required fields are marked *