Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

POLAND'S CERT WARNS OF ACTIVE EXPLOITATION OF CRITICAL ZIMBRA COLLABORATION SUITE FLAW, EXPOSED BY APT GROUPS




Poland's CERT has warned of the active exploitation of a critical vulnerability in the Zimbra Collaboration Suite, which allows unauthenticated remote code execution. The vulnerability was patched less than a month ago, but threat actors are already actively exploiting it. Organizations in sectors targeted by Russian or Chinese state-backed groups should treat unpatched Zimbra servers as a high priority and take immediate action to protect themselves against this vulnerability.



  • Poland's CERT has issued an alert about a critical vulnerability in Zimbra Collaboration Suite (CVE-2026-73570) that allows remote code execution.
  • The vulnerability was patched less than a month ago, but threat actors are actively exploiting it.
  • The attack surface is smaller than the exposed number of Zimbra servers, but the exact number is unknown.
  • The CERT team recommends verifying Zimbra logs and files created by the user zimbra in the last 30 days.
  • Organizations in sectors targeted by Russian or Chinese state-backed groups should treat unpatched Zimbra servers as a high priority.



  • Poland's CERT has issued an alert regarding the active exploitation of a critical vulnerability in the Zimbra Collaboration Suite. The vulnerability, identified as CVE-2026-73570, is a remote code execution (RCE) flaw that allows unauthenticated attackers to execute arbitrary shell commands with the privileges of the zimbra user. The CERT team has confirmed that threat actors are actively exploiting this vulnerability, which was patched less than a month ago.

    The vulnerability affects systems with SNMP trap notifications enabled and the swatchdog service running, which is enabled by default. The technical root cause is a sanitization failure in the SNMP monitoring component. Zimbra released version 10.1.20 on July 20, 2026, to address the issue. However, due to the rapid exploitation of the vulnerability, the CERT team has recommended verifying Zimbra logs and verifying files created by the user zimbra in the last 30 days.

    The attack surface is smaller than the exposed number of Zimbra servers, which are reachable from the Internet and tracked by Shadowserver. The real attack surface is estimated to be smaller, but the exact number is unknown. CERT Polska has published indicators of compromise alongside the advisory, giving administrators specific places to look for signs of potential exploitation.

    The absence of CVE-2026-73570 in CISA's Known Exploited Vulnerabilities catalog does not mean the threat is lower. It means the catalog has not caught up yet. Zimbra solutions have been targeted by nation-state actors for years, and Russian espionage groups have exploited similar vulnerabilities in the past.

    Organizations in sectors targeted by Russian or Chinese state-backed groups should treat unpatched Zimbra servers as a high priority. The conditions make the flaw an attractive target for rapid exploitation. The CERT team has recommended that administrators take immediate action to verify the logs and files created by the user zimbra and contact the team if they discover any signs of potential exploitation.

    The exploitability of CVE-2026-73570 has significant implications for organizations that use Zimbra Collaboration Suite. The fact that threat actors are actively exploiting this vulnerability highlights the need for prompt patching and proper monitoring. The CERT team's recommendations serve as a warning to organizations to take proactive measures to protect themselves against this vulnerability.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/POLANDS-CERT-WARNS-OF-ACTIVE-EXPLOITATION-OF-CRITICAL-ZIMBRA-COLLABORATION-SUITE-FLAW-EXPOSED-BY-APT-GROUPS-ehn.shtml

  • https://securityaffairs.com/197610/security/polands-cert-warns-of-active-exploitation-of-critical-zimbra-collaboration-suite-flaw.html

  • https://nvd.nist.gov/vuln/detail/CVE-2026-73570

  • https://www.cvedetails.com/cve/CVE-2026-73570/


  • Published: Fri Aug 21 06:16:10 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us