Hackers Exploit Patched Zimbra Vulnerability in Active Campaigns

CERT Polska warns of active attacks targeting a recently patched Zimbra SNMP vulnerability that allows unauthenticated remote code execution.

By Central
CVE-2026-73570 affects Zimbra's optional SNMP package, enabling unauthenticated command execution.
Highlights
  • The vulnerability in the zimbra-snmp package allows unauthenticated attackers to execute arbitrary commands on the server.
  • CERT Polska confirmed active exploitation campaigns this week and released indicators of compromise.
  • Organizations must prioritize patching to version 10.1.20 or disable SNMP notifications to mitigate risk.

A recently patched vulnerability in Zimbra Collaboration, tracked as CVE-2026-73570, is now being actively exploited in real-world attacks, according to an alert issued by Poland’s CERT Polska. The warning, published this week, confirms that adversaries are moving quickly to target systems that have not yet applied the security update released on July 20 with version 10.1.20 of the enterprise email and collaboration suite.

What Is CVE-2026-73570 and How Does the Exploit Work?

This high-severity security flaw resides in the optional ‘zimbra-snmp’ package, a component that enables Simple Network Management Protocol (SNMP) notifications within the Zimbra environment. When this package is installed and SNMP notifications are enabled, the vulnerability allows an unauthenticated attacker to execute arbitrary operating system commands under the context of the Zimbra user. This is a critical distinction: no authentication is required, and no user interaction is needed to trigger the exploit.

The technical mechanism behind CVE-2026-73570 involves improper handling of input passed to SNMP-related functions. Because the Zimbra user typically has broad system privileges—including access to mail stores, configuration files, and database connections—command execution at this level effectively gives an attacker the keys to the entire server. Once initial access is gained, the threat actor can pivot to more destructive actions such as credential harvesting, email exfiltration, lateral movement across the network, and persistence establishment.

Why SNMP Matters for This Vulnerability

SNMP is a widely used protocol for monitoring and managing network devices and servers. In enterprise deployments, SNMP notifications are often enabled to integrate Zimbra with centralized monitoring systems like Nagios, Zabbix, or SolarWinds. Organizations that rely on such monitoring may have the vulnerable package installed without realizing its exposure. The attack surface is therefore not universal—it is specific to configurations where the ‘zimbra-snmp’ package is active. IT administrators should verify whether their Zimbra instances include this package and, if so, ensure immediate patching or disable SNMP notifications until the update can be applied.

Active Exploitation Campaigns: What CERT Polska Has Detected

CERT Polska, the national computer security incident response team for Poland, announced that it has observed active exploitation of CVE-2026-73570 this week. The team did not release specific technical details about the campaign’s origin, scale, or methodology beyond confirming that attacks are underway. However, CERT Polska did share a set of indicators of compromise (IoCs) on its advisory page, enabling defenders to check their logs for signs of malicious activity. These IoCs typically include IP addresses, file hashes, and network signatures associated with the exploitation attempts.

The lack of detailed attribution from CERT Polska is not unusual in the early stages of an active campaign. Threat actors often obfuscate their infrastructure and use compromised servers as relay points, making immediate identification difficult. Nevertheless, the operational tempo of these attacks suggests that the exploit code may already be circulating among multiple threat groups, including both state-sponsored actors and financially motivated cybercriminals.

What Are the Indicators of Compromise?

The IoCs released by CERT Polska are available through their official advisory portal. While the exact list is updated regularly to reflect new findings, typical IoCs for this type of exploit include suspicious outbound connections from the Zimbra server on unusual ports, the creation of unexpected files in the /tmp directory, and unauthorized modifications to system binaries. Administrators should also monitor for command execution patterns that invoke shell commands via the SNMP interface, as well as any attempts to download additional payloads from remote servers. Checking these indicators with security information and event management (SIEM) tools can help identify breaches before full compromise occurs.

Understanding the Risk: From Server Control to Full Network Compromise

The exploitation of CVE-2026-73570 represents more than just a server-level vulnerability. Zimbra Collaboration Suite is a central component in many organizations’ email and communication infrastructure. It stores sensitive email communications, calendar entries, contact lists, and often integrates with directory services like LDAP or Active Directory. When an attacker gains code execution as the Zimbra user, they can read all email traffic, reset passwords, intercept two-factor authentication tokens, and map internal network topology.

From there, the attacker can mount further attacks: lateral movement to adjacent systems, privilege escalation to domain administrator, deployment of ransomware, or sustained espionage. In previous Zimbra exploitation campaigns, attackers have been observed establishing backdoors that persist through software updates, creating hidden administrator accounts, and exfiltrating gigabytes of email data over long periods before detection. The consequences for affected organizations can include regulatory fines, reputational damage, intellectual property theft, and operational disruption.

Historical Context: Zimbra as a Target for Sophisticated Hackers

Zimbra’s popularity in the enterprise and government sectors—particularly among organizations that prefer self-hosted email over cloud services—has made it a frequent target. The product’s Java-based architecture, combined with the complexity of its deployment options, has historically yielded a steady stream of vulnerabilities. Over the years, exploitation of Zimbra flaws has been attributed to advanced persistent threat (APT) groups sponsored by Russia and China, as well as to cybercriminal collectives seeking to turn email access into financial profit.

For instance, Russian state-sponsored hackers have exploited Zimbra vulnerabilities to target NATO entities, while Chinese-linked groups have used similar techniques against diplomatic missions and defense contractors. The dual-use nature of these exploits—equally effective for espionage and for financial crime—means that any new vulnerability is likely to attract attention from multiple quarters simultaneously. CVE-2026-73570 appears to be following this pattern, with active exploitation detected before any formal attribution has been established.

Why This Vulnerability Hasn’t Been Added to CISA’s KEV Catalog Yet

The U.S. Cybersecurity and Infrastructure Security Agency maintains a Known Exploited Vulnerabilities (KEV) catalog that serves as a critical resource for federal agencies and private sector defenders. Currently, the KEV catalog lists 18 Zimbra Collaboration Suite vulnerabilities, including four that were added in 2026 alone. However, CVE-2026-73570 has not yet been added to the catalog as of this writing.

The delay may reflect the normal operational timeline of the KEV process. CISA typically adds vulnerabilities to the catalog only after independent confirmation of active exploitation by multiple reliable sources. While CERT Polska’s alert is a strong signal, the agency may be awaiting additional telemetry from other national CERTs or from its own threat intelligence partners before taking action. Once added, the vulnerability will be placed under a binding operational directive for U.S. federal civilian agencies, requiring immediate patching within a mandated timeframe. Private sector organizations are strongly advised to treat CERT Polska’s report as sufficient evidence to prioritize patching, regardless of whether CISA has formally listed the flaw.

What Does the CISA KEV Catalog Include for Zimbra?

The 18 Zimbra vulnerabilities already in the KEV catalog span a range of severity levels and attack vectors, from cross-site scripting and SQL injection to remote code execution and authentication bypass. Many of these have been exploited in the wild by various threat actors. The recurring theme is that Zimbra vulnerabilities tend to be reliably exploitable, provide high-value access, and are frequently incorporated into the toolkits of both state-sponsored and criminal groups. The addition of CVE-2026-73570 to the catalog is likely a matter of time, given the severity and the active exploitation now confirmed.

What Organizations Should Do Right Now

The most effective mitigation for CVE-2026-73570 is to upgrade to Zimbra Collaboration version 10.1.20 or later, which contains the security patch. Organizations that cannot immediately upgrade should consider disabling the ‘zimbra-snmp’ package and turning off SNMP notifications as a temporary workaround. Additionally, network segmentation can limit the blast radius of a potential compromise by restricting the Zimbra server’s access to only necessary internal systems.

IT teams should also conduct a thorough forensic review of their Zimbra server logs, looking for any signs of unauthorized command execution or unusual network traffic patterns. The IoCs provided by CERT Polska can serve as a starting point for this analysis. If evidence of compromise is found, incident response procedures should be initiated without delay, including credential rotation, system reimaging, and coordination with law enforcement or national cybersecurity authorities.

Are There Any Alternative Mitigations?

For environments where patching is delayed due to compatibility testing or change management procedures, deploying a web application firewall (WAF) with custom rules to block SNMP-related command injection attempts may provide a partial defense. Intrusion detection systems (IDS) can also be tuned to alert on signatures associated with this exploit. However, these are stopgap measures and should not substitute for applying the vendor-supplied patch. The most reliable protection remains updating to the fixed version.

Broader Implications for Email Security and Enterprise Collaboration

This incident underscores a persistent challenge in enterprise security: the tension between functionality and exposure. SNMP is a valuable tool for monitoring, but its integration into a complex product like Zimbra creates unintended attack surfaces. The vulnerability exists not because of a fundamental flaw in SNMP itself, but because of how the Zimbra implementation handles user input within that context. This pattern—where optional features introduce unexpected risk—is common across enterprise software suites and requires diligent attack surface management.

Organizations are increasingly adopting zero-trust principles, but legacy email systems like Zimbra often predate these architectures. The result is that many Zimbra deployments are treated as trusted internal services, with broad network access and elevated privileges. As attackers continue to target these central systems, the importance of regular patching, vulnerability scanning, and configuration hardening cannot be overstated.

Looking at the Threat Landscape: Who Might Be Behind These Attacks?

While CERT Polska has not attributed the current campaign to any specific threat actor, the historical pattern of Zimbra exploitation provides strong clues. Russian military intelligence units such as APT28 and Chinese groups like APT31 have both used Zimbra vulnerabilities in past operations, typically targeting government ministries, defense contractors, and diplomatic missions. The ongoing geopolitical tensions involving Poland—a NATO member state that has been a frequent target of Russian cyber operations—adds another layer of context. It is plausible that the exploitation detected by CERT Polska is part of a broader espionage campaign targeting Polish or European institutions.

At the same time, financially motivated groups should not be ruled out. The availability of exploit code on cybercrime forums could quickly democratize access to this vulnerability, allowing less sophisticated actors to deploy ransomware or conduct business email compromise (BEC) attacks. Whether the current wave of exploitation represents a single group or multiple independent actors remains unclear, but the risk to all Zimbra users is the same.

For the foreseeable future, enterprises running Zimbra should expect that any unpatched vulnerability with remote code execution potential will be actively targeted. The window between patch release and weaponization continues to shrink, and the need for rapid patch management has never been greater.

Final Practical Guidance for Security Teams

Defenders should treat CVE-2026-73570 with the same urgency as a zero-day exploit, even though a patch exists. The fact that active exploitation has been confirmed by a national CERT means that attackers are already scanning for and compromising vulnerable servers. Prioritize patching above all other non-critical maintenance tasks. Review firewall rules to ensure that the Zimbra server is not directly exposed to the internet unless absolutely necessary. Implement logging and alerting that can detect the specific indicators shared by CERT Polska. And finally, rehearse your incident response plan for email server compromise, because the next attack—whether from this vulnerability or the next one—may come sooner than anticipated.

Share This Article