Security3 distinct publishers3 min readUpdated
CERT Polska says CVE-2026-73570 is under active exploitation. The fix shipped on July 20, and whether SNMP notifications are enabled, not the version string alone, sets the blast radius.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
CERT Polska says CVE-2026-73570 is under active exploitation. The fix shipped on July 20, and whether SNMP notifications are enabled, not the version string alone, sets the blast radius.
CERT Polska reported on Monday that threat actors are actively exploiting CVE-2026-73570, a command injection flaw in Zimbra Collaboration Suite that gives unauthenticated attackers remote code execution [1][6]. Shadowserver currently tracks more than 12,100 Zimbra servers exposed online, and there is no public figure for how many of those have already applied the fix or are honeypots [7][10].
The patch is not new. Zimbra shipped version 10.1.20 on July 20 to close the hole [3]. According to the advisory, improper sanitization of untrusted input during SNMP notification processing lets an unauthenticated attacker send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user [5].
Two details in that sentence matter more than the CVSS-shaped panic around it. First, the vulnerable path is the SNMP monitoring component and it is reachable when SNMP notifications are enabled [4]. Version inventory alone will not tell you whether a given host was ever a target; the notification configuration does. Second, code runs as the zimbra service account, not root [5]. That is not comforting - the zimbra user owns the mail store and the Jetty webapp directories - but it does shape what post-exploitation looks like and what a containment plan needs to cover.
CERT Polska's hunting guidance is concrete, which is rare enough to follow literally. Admins are asked to check logs for suspicious activity such as the Zimbra service restarting on its own, and for files created by user zimbra in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/ and /tmp/ over the last 30 days [8]. The 30-day window is the tell: the assumption is that exploitation may predate the public warning, so patching now without looking backwards leaves a webshell in place on a host you have declared clean.
Scale is what makes this worth the effort. Zimbra is used by hundreds of millions of people and organizations, including thousands of businesses and hundreds of government agencies [2]. Of the exposed servers Shadowserver counts, 4,382 are in Europe and 4,492 in Asia [7], which is 8,874 between them, or roughly 73 percent of the total [11].
The attacker interest is established rather than speculative. Russian-linked Winter Vivern used a reflected XSS exploit against Zimbra webmail in February 2023 to steal email from NATO-aligned targets [12]; US and UK agencies warned in October 2024 that APT29 was targeting vulnerable Zimbra servers [13]; and in March, Seqrite Labs reported APT28 exploiting a stored XSS flaw against Ukrainian government ZCS servers [14].
What to watch: whether the Shadowserver exposure count falls meaningfully in the next few weeks, since a patch a month old that is still the deciding control implies slow uptake [3][7]; whether anyone publishes indicators beyond file-creation paths, which would let defenders distinguish scanning from successful execution [8]; and whether the espionage groups with Zimbra track records adopt this chain, given they have historically preferred credential and email theft over noisy shells [12][13][14].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
CERT Polska, the Polish Computer Emergency Response Team, warned that attackers have begun exploiting a critical vulnerability in Zimbra Collaboration Suite (ZCS).
The Zimbra security team released version 10.1.20 on July 20 to patch the vulnerability tracked as CVE-2026-73570.
CVE-2026-73570 allows unauthenticated attackers to gain remote code execution by exploiting a command injection weakness in the SNMP monitoring component when SNMP notifications are enabled.
Advisory text: "Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user."
On Monday, the Polish CERT team reported that threat actors are now exploiting CVE-2026-73570 in attacks, describing it as an actively used OS Command Injection vulnerability in Zimbra Collaboration Suite.
CERT Polska asked admins to check logs for suspicious activity such as the Zimbra service restarting on its own, and for files created in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/ and /tmp/ by user zimbra over the last 30 days.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Named CERT plus NVD record, but exploitation details withheld
Exploitation is asserted by a named national CERT and corroborated identically by three independent outlets, and the vulnerability mechanics are anchored in the NVD description with a CVSS score and a precise affected-version boundary. Evidence stops short of proof of impact: CERT Polska published IoCs but no attack telemetry, no victim count, and no attribution, and the two severity labels in circulation (critical versus high, CVSS 8.9) are not reconciled.
Exposure counted, exploited and patched shares unmeasured
There is real measurement of the deployed attack surface: Shadowserver tracks over 12,100 internet-facing Zimbra servers, concentrated in Asia and Europe, and a fix has been generally available since July 20. But the operationally decisive quantities are missing: how many of those hosts run the optional zimbra-snmp package with notifications enabled, how many have taken 10.1.20, and how many were actually hit. Exposure breadth is therefore established while exploitation scale is not.
Headline exposure number overstates the vulnerable set
Mild overstatement. The 12,100 figure counts internet-facing Zimbra servers, not hosts meeting the two required conditions of an installed zimbra-snmp package plus enabled SNMP notifications, yet it functions in coverage as a proxy for blast radius. One outlet labels the flaw critical while the NVD score is 8.9 and another calls it high-severity, and CISA has not yet listed it as known-exploited. Offsetting this, the underlying facts are real: unauthenticated RCE, a confirmed CERT exploitation report, and a documented history of state-linked Zimbra targeting, so the gap is modest rather than promotional.
CERT-sourced reporting with one embedded vendor pitch
The primary sourcing is non-commercial: a national CERT bulletin, the NIST NVD record, Shadowserver scan data, and CISA's KEV catalog, none of which sell a remediation product. The main incentive artifact is editorial rather than analytical: the BleepingComputer article appends a sponsored breach-and-attack-simulation report promotion to the security warning, and all three outlets operate in an attention economy where 'critical RCE actively exploited' framing performs well. No source has a disclosed financial stake in the Zimbra ecosystem.
Core facts firm, impact and scale still open
High confidence in the patch timeline, the vulnerability mechanism and its configuration preconditions, and the fact that CERT Polska has declared active exploitation, since three independent publishers agree and primary records back the technical detail. Lower confidence in anything about magnitude: exploited host counts, attribution, patch uptake, and the prevalence of the vulnerable SNMP configuration are all unreported, and severity labelling is inconsistent across outlets.
build
A UDP packet is now enough: IKEEXT RCE moves from patch queue to fire drill1 distinct publisher
security
SharePoint flaw went from PoC to honeypot hits in a day, and Microsoft's advisory is still silent1 distinct publisher
security
Ukraine's asset agency was attacked on the tender calendar, not the network map2 distinct publishers
security
One packet reboots your Cisco VPN box, and Cisco will not say who is firing it1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 20, 2026
1 article · August 20, 2026
1 article · August 20, 2026