Skip Navigation

August 20, 2026 |

Active exploitation of Zimbra Collaboration flaw

Loading table of contents...

At a glance:

  • CERT Polska has reported active exploitation of a recently patched Zimbra Collaboration vulnerability.

  • Under specific conditions, the vulnerability can allow an unauthenticated threat actor to execute operating system commands as the Zimbra user account.

  • Organizations should determine if the optional zimbra-snmp package is installed and SNMP notifications are enabled. If the vulnerable configuration is present, update to version 10.1.20 and review systems for indicators of compromise.

Threat summary

On August 17, 2026, the Polish Computer Emergency Response Team (CERT Polska) reported active exploitation of a recently patched vulnerability in Zimbra Collaboration. The advisory comes after Zimbra's July 20, 2026 release of version 10.1.20, which addressed the issue.

Zimbra Collaboration (formerly Zimbra Collaboration Suite) is a self-hosted email and collaboration platform used by enterprises, educational institutions, government organizations, and service providers. Because the platform hosts email, calendars, contacts, and administrative services, a compromised Zimbra server can expose sensitive business communications and provide access to systems used for authentication and user management.

The vulnerability, tracked as CVE-2026-73570, is rated High severity with a CVSS score of 8.9.

It affects Zimbra Collaboration's Simple Network Management Protocol (SNMP) monitoring functionality and is caused by improper sanitization of untrusted input during notification processing. In deployments where the optional zimbra-snmp package is installed and SNMP notifications are enabled, an unauthenticated threat actor can send specially crafted requests that result in arbitrary operating system command execution as the Zimbra user account. The practical impact depends on the permissions assigned to that account and the data, applications, and services accessible from the affected mail server.

Analysis

Government agencies and researchers have documented multiple campaigns targeting Zimbra vulnerabilities in recent years, including operations associated with intelligence collection and credential theft.

Zimbra has been repeatedly targeted by threat actors because email systems contain high-value information and often provide insight into business operations, user relationships, and authentication workflows. Access to mailboxes, stored communications, administrative functions, and locally available credentials depends on the configuration of the affected server.

Identifying Zimbra deployments is not always straightforward because the product has changed ownership several times over the past two decades. Depending on when a system was deployed and how software inventories are maintained, the platform may appear under vendor names such as Zimbra, Zextras, Synacor, VMware, Telligent, or Yahoo!. The product itself may be listed as Zimbra Collaboration, Zimbra Collaboration Suite (ZCS), or Zimbra Collaboration Server.

Organizations reviewing asset inventories, vulnerability scans, configuration management databases, or software procurement records may need to search for these legacy names to locate all Zimbra installations. Older systems are particularly likely to retain historical vendor information after product upgrades or ownership changes.

Mitigations

Organizations operating internet-facing Zimbra servers that have the optional zimbra-snmp package installed and SNMP notifications enabled warrant immediate attention because these conditions are required for the exploitation activity currently being observed.

Organizations running earlier Zimbra versions without these features enabled can incorporate the upgrade to version 10.1.20 into their normal patch management cycle.

CERT Polska also recommends examining /var/log/zimbra.log for unexpected service activity and reviewing files created by the Zimbra user in:

  • /opt/zimbra/jetty/webapps/

  • /opt/zimbra/jetty_base/webapps/

  • /tmp/

Unauthorized files, scripts, web applications, or recent changes in those locations warrant investigation and a review of potentially affected credentials.

ThreatRoundUp_SignUp_Simplifiedx2

Stay on top of emerging threats like this.

Sign up to receive a weekly roundup of our security intelligence feed. You'll be the first to know of emerging attack vectors, threats, and vulnerabilities. 

Sign up