Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Critical Vulnerability in Zimbra Collaboration Suite Exploited by Threat Actors



The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in the Zimbra Collaboration Suite (ZCS) to its Known Exploited Vulnerabilities (KEV) catalog, confirming that threat actors are actively exploiting it. Organizations must take immediate action to patch the vulnerability and ensure the security of their networks.

  • There is a critical vulnerability in the Zimbra Collaboration Suite (ZCS) that allows an unauthenticated attacker to execute arbitrary shell commands with the privileges of the zimbra user.
  • The vulnerability, CVE-2026-73570, affects systems with SNMP trap notifications enabled and the swatchdog service running.
  • The fix was released by Zimbra on July 20, 2026, but the attack surface only exists when the optional zimbra-snmp package is installed and SNMP notifications are active.
  • CERT Polska recommends verifying Zimbra logs and files created by the user zimbra in the last 30 days.
  • CISA orders federal agencies to fix the flaw by August 24, 2026, and experts recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.



  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in the Zimbra Collaboration Suite (ZCS) to its Known Exploited Vulnerabilities (KEV) catalog. This move comes after Poland's national computer emergency response team, CERT Polska, confirmed that threat actors are actively exploiting this vulnerability. The vulnerability, identified as CVE-2026-73570, allows an unauthenticated attacker to execute arbitrary shell commands with the privileges of the zimbra user.

    The vulnerability affects systems with SNMP trap notifications enabled and the swatchdog service running, which is enabled by default on most installations. The technical root cause of the vulnerability is a sanitization failure in the SNMP monitoring component. Zimbra released version 10.1.20 on July 20, 2026, to address the issue, but the fix came 28 days before active exploitation was confirmed, which is not a wide window.

    Due to the ongoing campaign exploiting this vulnerability, CERT Polska recommends verifying Zimbra logs and files created by user zimbra in the last 30 days in specific directories. If any signs of potential exploitation are discovered, the team should be contacted immediately. CISA orders federal agencies to fix the flaw by August 24, 2026, and experts recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

    The attack surface of this vulnerability only exists when the optional zimbra-snmp package is installed and SNMP notifications are active, but the swatchdog service is running by default. The fact that threat actors are actively exploiting this vulnerability makes it essential for organizations to take immediate action to patch the vulnerability and ensure the security of their networks.

    The CERT Polska team informs about an actively exploited OS Command Injection vulnerability in Zimbra Collaboration Suite. The vulnerability, identified as CVE-2026-73570, allows an unauthenticated attacker to execute arbitrary shell commands with the privileges of the zimbra user. The vulnerability affects instances that have the SNMP trap service enabled via the snmp_notify parameter and the swatchdog service running, which is enabled by default.

    Zimbra released version 10.1.20 on July 20, 2026, to address the issue. The fix came 28 days before active exploitation was confirmed, which is not a wide window. The technical root cause of the vulnerability is a sanitization failure in the SNMP monitoring component. The attack surface of this vulnerability only exists when the optional zimbra-snmp package is installed and SNMP notifications are active, but the swatchdog service is running by default.

    Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure. CISA orders federal agencies to fix the flaw by August 24, 2026. The fact that threat actors are actively exploiting this vulnerability makes it essential for organizations to take immediate action to patch the vulnerability and ensure the security of their networks.

    In conclusion, the critical vulnerability in the Zimbra Collaboration Suite (ZCS) is a serious security concern that requires immediate attention from organizations. The fact that threat actors are actively exploiting this vulnerability makes it essential for organizations to take immediate action to patch the vulnerability and ensure the security of their networks.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Critical-Vulnerability-in-Zimbra-Collaboration-Suite-Exploited-by-Threat-Actors-ehn.shtml

  • https://securityaffairs.com/197693/security/u-s-cisa-adds-zimbra-collaboration-suite-zcs-flaw-to-its-known-exploited-vulnerabilities-catalog.html

  • https://nvd.nist.gov/vuln/detail/CVE-2026-73570

  • https://www.cvedetails.com/cve/CVE-2026-73570/


  • Published: Sat Aug 22 03:44:46 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us