Cyber Security News

Zimbra Collaboration Suite Vulnerability Actively Exploited in the Wild

CERT Polska has warned that threat actors are actively exploiting CVE-2026-73570, a critical OS command-injection vulnerability in Zimbra Collaboration Suite that allows remote, unauthenticated attackers to execute arbitrary shell commands as the zimbra user.

The vulnerability affects Zimbra installations in which the SNMP trap service is enabled via the snmp_notify parameter and the swatchdog service is running.

Since swatchdog is enabled by default, exposed servers with SNMP notifications configured may face a heightened risk of compromise. Successful exploitation could give attackers a foothold on vulnerable mail servers without requiring valid credentials.

From there, attackers may execute malicious commands, create or modify files, deploy web shells, steal email data, establish persistence, or use the compromised server to target other systems within an organization.

Zimbra Collaboration Suite Vulnerability Exploited

CERT Polska said the issue has already been observed in an ongoing exploitation campaign. Organizations using Zimbra Collaboration Suite should therefore treat the vulnerability as an immediate incident-response and patch-management priority rather than a routine software update.

Zimbra fixed CVE-2026-73570 in version 10.1.20. Administrators should verify the installed Zimbra version and upgrade affected systems to a patched release as soon as possible.

Systems that cannot be updated immediately should be reviewed for whether SNMP trap functionality is necessary and whether the snmp_notify configuration is enabled.

Security teams should also inspect Zimbra logs for suspicious changes in service status. Relevant entries may show an unfamiliar service or command payload changing from “stopped” to “running,” or from “running” to “stopped.”

These events may indicate that an attacker used the vulnerable component to trigger malicious commands through the swatchdog service.

Administrators should specifically review /var/log/zimbra.log for unexpected “Service status change” records. Any service names, command strings, or payloads that do not match normal operational activity should be investigated.

CERT Polska also recommends checking for recently created files owned by the zimbra user. The highest-priority directories include /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/.

Web application directories are especially important because attackers often place JSP-based web shells or other malicious application files there to maintain remote access after initial exploitation.

Files created or modified in the past 30 days should be reviewed for unusual names, obfuscated code, unexpected archive files, executable scripts, unauthorized JSP files, and outbound network activity associated with the Zimbra server.

If signs of compromise are found, organizations should isolate the affected server, preserve logs and suspicious files for forensic analysis, rotate potentially exposed credentials, and investigate connected systems for lateral movement. CERT Polska has requested that evidence of suspected exploitation be reported to its incident-response team.

The active exploitation of CVE-2026-73570 highlights the continued targeting of internet-facing email infrastructure. Prompt patching, log review, and web-shell hunting are essential to reduce the risk of a full Zimbra server compromise.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

ASOS Warns Customer Accounts Were Accessed Using Compromised Login Credentials

ASOS US Sales LLC reported unauthorized access to customer accounts using credentials obtained from outside…

4 minutes ago

Eight AI Agents Breach Government Systems, Crack 85 Accounts and Steal 2,500+ Records

A near-autonomous cyberattack using open-source AI agent frameworks compromised government systems in Asia, cracked 85…

7 minutes ago

Fake Microsoft Security Scan Tells You to Remove Antivirus—Then Scammers Ask for Remote Access

A new web-based scam is using fake Microsoft-branded security scans to frighten people into removing…

7 minutes ago

AliExpress Uses WebAudio API and Zero-Gain Audio Graphs for Silent Device Fingerprinting

AliExpress's homepage quietly builds hidden WebAudio processing graphs in the browser, a technique that appears…

11 minutes ago

Tata’s B2B Platform Flaw Enables Account Takeover Just by Knowing Victim’s Phone Number

A critical authentication flaw in Tata Nexarc, a B2B procurement platform for small and medium…

17 minutes ago

ClickFix Campaigns Deploy PavinLoader With Blockchain-Based C2 and Amatera Stealer

ClickFix campaigns are turning routine web prompts into Windows infections. A tracked loader, PavinLoader, is…

1 hour ago