Critical RCE Vulnerability in Zimbra Exploited by Attackers

Critical RCE Vulnerability in Zimbra Exploited by Attackers

First seen 19 Aug 2026, 22:48 UTC Ccb.Belgium.Bemoje.cert.plcvefeed.ioBleepingcomputerThehackernews+12 79.0

Article Content

Browse articles
ThreatCluster

A critical remote code execution vulnerability (CVE-2026-73570) in Zimbra Collaboration Suite is being actively exploited by attackers. The flaw, which affects versions prior to 10.1.20, allows unauthenticated attackers to execute arbitrary commands as the Zimbra user through improper input sanitization in SNMP notification processing. CERT Polska reported that over 12,100 Zimbra servers are exposed online, primarily in Europe and Asia. Security teams are urged to check logs for suspicious activity and to patch systems immediately. The vulnerability has a CVSS score of 8.9, indicating high severity. Previous Zimbra vulnerabilities have been exploited by state-sponsored groups, raising concerns about the potential for significant breaches. Organizations are advised to enhance monitoring and detection capabilities to mitigate risks.

Key Points: • CVE-2026-73570 allows unauthenticated remote code execution in Zimbra Collaboration Suite. • Over 12,100 Zimbra servers are exposed, mainly in Europe and Asia, increasing risk of exploitation. • Immediate patching to version 10.1.20 is recommended to protect against this critical vulnerability.

Timeline

2026-08-13
CVE-2026-73570 published
A remote code execution vulnerability in Zimbra Collaboration Suite was officially disclosed.
cvefeed.io
2026-08-19
Active exploitation reported
CERT Polska confirmed that attackers are actively exploiting CVE-2026-73570 in the wild.
Bleepingcomputer
2026-08-19
Security advisory issued
The Centre for Cybersecurity Belgium issued a warning and recommended immediate patching of Zimbra systems.
Ccb.Belgium.Be
2026-08-20
Patch released
Zimbra released version 10.1.20 to address the critical vulnerability CVE-2026-73570.
Bleepingcomputer