Poland's CERT warns of active attacks on critical Zimbra email flaw
CERT Polska says attackers are exploiting CVE-2026-73570 in Zimbra Collaboration Suite. Zimbra patched the bug in version 10.1.20 on 20 July 2025.

Key points
- CERT Polska, Poland's national cyber incident team, reported on Monday that attackers are actively exploiting a critical flaw in Zimbra Collaboration Suite, a widely used business email platform.
- The bug, CVE-2026-73570, lets an unauthenticated attacker run commands on the server through the software's SNMP monitoring feature.
- Zimbra released a fix in version 10.1.20 on 20 July 2025.
- Shadowserver tracks more than 12,100 Zimbra servers reachable from the public internet, with the largest concentrations in Asia and Europe.
- Admins should check for unexpected service restarts and suspicious files written by the zimbra user in the last 30 days.
Poland's national cyber response team has flagged a serious flaw in Zimbra Collaboration Suite as under active attack. Zimbra is used by governments, businesses and universities to run email and shared calendars. The warning came in a Monday advisory from CERT Polska, first reported by BleepingComputer.
What is the flaw?
The bug is tracked as CVE-2026-73570, a critical remote code execution issue in Zimbra's SNMP notification handling. The part of Zimbra that sends out monitoring alerts doesn't properly clean up the input it receives, so a specially crafted request can smuggle in operating system commands.
No login is required. Any server with SNMP notifications switched on and reachable from the internet is a target. Zimbra shipped a fix in version 10.1.20 on 20 July 2025, and servers still on older builds remain exposed.
We've covered Zimbra five times in the last 90 days, including a 23 July report on LAUNDRY BEAR exploiting a separate Zimbra flaw to steal email without a victim doing more than opening a message. CVE-2026-73570 is a different entry point, but the target is the same.
Who is at risk?
Organisations running their own Zimbra mail servers. Shadowserver, a non-profit that scans the internet for exposed systems, tracks 4,492 in Asia and 4,382 in Europe. Not all are vulnerable; some may be honeypots. But the pool of potential victims is large, and there's no public count of how many have already patched.
| Item | Detail |
|---|---|
| CVE | CVE-2026-73570 |
| Fixed version | Zimbra 10.1.20 |
| Patch released | 20 July 2025 |
| Active exploitation confirmed | CERT Polska, Monday advisory |
| Exposed servers online | 12,100+ (Shadowserver) |
What should admins check?
CERT Polska has published concrete indicators. Watch for Zimbra restarting on its own without a scheduled reason. Check the folders /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/ and /tmp/ for files created by the zimbra user in the last 30 days. Unexpected files there can signal a web shell, a small script that hands the attacker a persistent back door.
Patching to 10.1.20 or later is the priority. Where that has to wait, disabling SNMP notifications removes the attack surface tied to this specific bug.
Why Zimbra keeps coming up
Zimbra servers hold sensitive mail and often sit at the network edge. In February 2023, Winter Vivern used a reflected cross-site scripting bug to steal mail from NATO-aligned targets. US and UK agencies warned in October 2024 that APT29, also known as Midnight Blizzard, was targeting Zimbra servers for email credentials. In March 2026, Seqrite Labs reported that APT28, linked to Russian military intelligence, was hitting Ukrainian government Zimbra systems through a stored XSS flaw.
Unpatched Zimbra gets found. It keeps getting found because it keeps not getting patched.
Common questions
Do end users need to do anything?
Not directly. This is a server-side flaw, so the fix falls to whoever runs your organisation's mail. If you're an admin, patch to 10.1.20 and hunt for the indicators CERT Polska listed.
Is my webmail login enough to trigger this?
No. The bug doesn't require any login. That's what makes it serious, and why exposed servers should be patched before anything else this week.



