CISA Directive and Vulnerability Details
The Cybersecurity and Infrastructure Security Agency (CISA) has formally ordered U.S. Federal Civilian Executive Branch agencies to secure their systems against an actively exploited security vulnerability affecting the Zimbra Collaboration Suite (ZCS). Tracked as CVE-2026-73570, the security flaw was patched by the Zimbra security team in version 10.1.20, which was released on July 20. The issue originates within the SNMP monitoring component of the collaboration software.
Successful exploitation of this weakness allows unauthenticated attackers to achieve remote code execution on targeted systems. The vulnerability specifically arises when SNMP notifications are enabled on the targeted system, due to improper sanitization of untrusted input during SNMP notification processing. By sending specially crafted Simple Mail Transfer Protocol (SMTP) requests, an unauthenticated attacker can cause the execution of arbitrary operating system commands as the Zimbra user.
The Zimbra security team previously released a software update addressing this security flaw in version 10.1.20 on July 20. However, subsequent real-world observations confirmed that the vulnerability is actively targeted by malicious actors in ongoing campaigns.
Discovery and Real-World Exploitation
CISA’s warning comes after CERT Polska, the Polish Computer Emergency Response Team, first flagged the vulnerability as targeted in the wild last Monday. On Friday, CISA confirmed CERT Polska’s alert, added the flaw to its Known Exploited Vulnerabilities catalog, and ordered U.S. Federal Civilian Executive Branch agencies to secure their systems within three days, by August 24.
Independent security organizations and threat watchdogs have monitored the widespread exposure and potential compromise of servers running the software. While threat security watchdog Shadowserver tracks more than 12,000 Zimbra servers exposed on the Internet, there is no information on how many are honeypots or have already been secured against attacks exploiting the CVE-2026-73570 flaw.
On Monday, Shadowserver also said it has found over 270 compromised Zimbra Collaboration Suite instances while looking for CVE-2026-73570 exploitation artifacts. Although CISA didn’t share any information on these ongoing attacks, the Polish CERT team asked security teams to check logs for suspicious activity, such as the Zimbra service restarting unexpectedly, and for files created in specific locations.
- Check for suspicious activity such as the Zimbra service restarting unexpectedly.
- Look for files created in the
/opt/zimbra/jetty/webapps/folder by user zimbra over the last 30 days. - Inspect the
/opt/zimbra/jetty_base/webapps/folder for files created by user zimbra over the last 30 days. - Examine the
/tmp/folder for files created by user zimbra over the last 30 days.
Context and Prior Targeting of Zimbra Software
ZCS is a popular email and collaboration suite used by hundreds of millions of organizations and people worldwide, including hundreds of government agencies and thousands of businesses. Zimbra security issues are commonly targeted in the wild and have been used to steal sensitive data from vulnerable email servers in recent years.
Most recently, Seqrite Labs researchers revealed in March that APT28, a state-sponsored threat group linked to Russia’s military intelligence service, was exploiting a stored cross-site scripting (XSS) vulnerability in attacks targeting Ukrainian government ZCS servers. In October 2024, U.S. and UK cyber agencies warned that APT29 hackers, tracked as Midnight Blizzard and Cozy Bear and linked to Russia’s Foreign Intelligence Service, were targeting Zimbra servers using a flaw previously exploited to steal email account credentials. Russian Winter Vivern cyber spies have also abused a reflected Cross-Site Scripting (XSS) vulnerability to steal emails belonging to NATO-aligned individuals and organizations via Zimbra webmail portals.
What happens next
U.S. Federal Civilian Executive Branch agencies are required to complete patching or mitigation of the CVE-2026-73570 vulnerability in accordance with CISA’s mandated three-day deadline by August 24.
Source: Original Article




