Zimbra Collaboration Suite actively exploited command injection RCE (CVE-2026-73570)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-73570 in Zimbra Collaboration Suite (ZCS) is being actively exploited for unauthenticated remote code execution through a command injection weakness in the SNMP monitoring component when SNMP notifications are enabled. Synacor released ZCS 10.1.20 on July 20 to patch the flaw, while CERT Polska and CISA flagged the vulnerability for urgent response. Shadowserver later reported 274 compromised instances seen on 2026-08-22, alongside at least 8200 unpatched instances in its scans.
Related Happenings
Zimbra Classic Web Client stored XSS cross-site scripting flaw
Vulnerability
H score22
First: 10.07.2026 14:47
Last: 10.07.2026 14:47
Sources 1
About this happening:
Zimbra's Classic Web Client stored cross-site scripting (XSS) flaw was patched in Zimbra 10.1.19, closing a path that could expose session data, account settings...
Zimbra Classic Web Client stored XSS cross-site scripting flaw
VulnerabilityAbout this happening: Zimbra's Classic Web Client stored cross-site scripting (XSS) flaw was patched in Zimbra 10.1.19, closing a path that could expose session data, account settings...
Zimbra Collaboration Suite actively exploited XSS flaw (CVE-2025-48700)
Vulnerability
H score74
First: 24.04.2026 16:35
Last: 24.04.2026 16:35
Sources 1
About this happening:
CVE-2025-48700 is an actively exploited XSS flaw in Zimbra Collaboration Suite (ZCS) that can let unauthenticated attackers run JavaScript inside a user's session and...
Zimbra Collaboration Suite actively exploited XSS flaw (CVE-2025-48700)
VulnerabilityAbout this happening: CVE-2025-48700 is an actively exploited XSS flaw in Zimbra Collaboration Suite (ZCS) that can let unauthenticated attackers run JavaScript inside a user's session and...
APT28 Operation GhostMail Zimbra phishing campaign targeting Ukrainian government entities
Campaign
H score37
First: 19.03.2026 16:55
Last: 19.03.2026 16:55
Sources 1
About this happening:
APT28’s Operation GhostMail is actively targeting Ukrainian government entities through a phishing chain that exploits CVE-2025-66376 in Zimbra Collaboration Sui...
APT28 Operation GhostMail Zimbra phishing campaign targeting Ukrainian government entities
CampaignAbout this happening: APT28’s Operation GhostMail is actively targeting Ukrainian government entities through a phishing chain that exploits CVE-2025-66376 in Zimbra Collaboration Sui...
CISA patch guidance for Zimbra and SharePoint flaws
Advisory/Mitigation
H score56
First: 19.03.2026 08:05
Last: 19.03.2026 08:05
Sources 1
About this happening:
CISA, NSA, and partner agencies issued a joint advisory on CVE-2025-66376, a stored XSS flaw in Zimbra Collaboration Classic UI that lets a crafted email r...
CISA patch guidance for Zimbra and SharePoint flaws
Advisory/MitigationAbout this happening: CISA, NSA, and partner agencies issued a joint advisory on CVE-2025-66376, a stored XSS flaw in Zimbra Collaboration Classic UI that lets a crafted email r...
CISA BOD 22-01 Zimbra patch order
Public Sector Action
H score34
First: 18.03.2026 21:57
Last: 18.03.2026 21:57
Sources 1
About this happening:
CISA ordered Federal Civilian Executive Branch agencies to secure Zimbra Collaboration Suite (ZCS) servers against CVE-2025-66376, an actively exploited flaw t...
CISA BOD 22-01 Zimbra patch order
Public Sector ActionAbout this happening: CISA ordered Federal Civilian Executive Branch agencies to secure Zimbra Collaboration Suite (ZCS) servers against CVE-2025-66376, an actively exploited flaw t...
Timeline
-
20.08.2026 03:00 3 articles · 14d ago
Zimbra releases 10.1.20 to patch CVE-2026-73570
Mitigation Patch UpdateThe Zimbra security team released version 10.1.20 for Zimbra Collaboration Suite on July 20 to fix CVE-2026-73570, a command injection flaw in the SNMP monitoring component that can let unauthenticated attackers gain remote code execution when SNMP notifications are enabled.
Show sources
- Critical Zimbra RCE flaw now actively exploited in attacks — www.bleepingcomputer.com — 20.08.2026 12:46
- CISA orders urgent patching of actively exploited Zimbra flaw — www.bleepingcomputer.com — 24.08.2026 13:45
- Hackers breached over 270 Zimbra servers in ongoing attacks — www.bleepingcomputer.com — 25.08.2026 15:04
-
20.08.2026 03:00 4 articles · 14d ago
CERT Polska warns that CVE-2026-73570 is being exploited
Initial DisclosureCERT Polska warned that attackers are exploiting CVE-2026-73570 in Zimbra Collaboration Suite, describing it as an actively used OS command injection flaw. Shadowserver tracks over 12,100 exposed Zimbra servers online, most in Europe and Asia, and admins were told to look for Zimbra services restarting on their own and unexpected files under /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/.
Show sources
- Critical Zimbra RCE flaw now actively exploited in attacks — www.bleepingcomputer.com — 20.08.2026 12:46
- Critical Zimbra RCE flaw now actively exploited in attacks — www.bleepingcomputer.com — 20.08.2026 12:46
- Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution — thehackernews.com — 20.08.2026 16:24
- Hackers Target Zimbra Servers in Active Exploitation Campaign — www.securityweek.com — 20.08.2026 17:50