Zimbra Collaboration Suite actively exploited command injection RCE (CVE-2026-73570)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-73570 in Zimbra Collaboration Suite (ZCS) is now actively exploited, giving attackers unauthenticated remote code execution against exposed servers. The flaw is a command injection issue in the SNMP monitoring component when SNMP notifications are enabled. Zimbra 10.1.20 was released on July 20 to patch the vulnerability, and exposed deployments remain a live target.
Related Happenings
APT28 Operation GhostMail Zimbra phishing campaign targeting Ukrainian government entities
Campaign
H score37
First: 19.03.2026 16:55
Last: 19.03.2026 16:55
Sources 1
About this happening:
APT28’s Operation GhostMail is actively targeting Ukrainian government entities through a phishing chain that exploits CVE-2025-66376 in Zimbra Collaboration Sui...
APT28 Operation GhostMail Zimbra phishing campaign targeting Ukrainian government entities
CampaignAbout this happening: APT28’s Operation GhostMail is actively targeting Ukrainian government entities through a phishing chain that exploits CVE-2025-66376 in Zimbra Collaboration Sui...
CISA patch guidance for Zimbra and SharePoint flaws
Advisory/Mitigation
H score56
First: 19.03.2026 08:05
Last: 19.03.2026 08:05
Sources 1
About this happening:
CISA, NSA, and partner agencies issued a joint advisory on CVE-2025-66376, a stored XSS flaw in Zimbra Collaboration Classic UI that lets a crafted email r...
CISA patch guidance for Zimbra and SharePoint flaws
Advisory/MitigationAbout this happening: CISA, NSA, and partner agencies issued a joint advisory on CVE-2025-66376, a stored XSS flaw in Zimbra Collaboration Classic UI that lets a crafted email r...
CISA BOD 22-01 Zimbra patch order
Public Sector Action
H score34
First: 18.03.2026 21:57
Last: 18.03.2026 21:57
Sources 1
About this happening:
CISA ordered Federal Civilian Executive Branch agencies to secure Zimbra Collaboration Suite (ZCS) servers against CVE-2025-66376, an actively exploited flaw t...
CISA BOD 22-01 Zimbra patch order
Public Sector ActionAbout this happening: CISA ordered Federal Civilian Executive Branch agencies to secure Zimbra Collaboration Suite (ZCS) servers against CVE-2025-66376, an actively exploited flaw t...
Digiever DS-2105 Pro active exploitation wave (CVE-2023-52163)
Exploitation Wave
H score39
First: 25.12.2025 10:07
Last: 25.12.2025 10:07
Sources 1
About this happening:
CVE-2023-52163 is being exploited at scale against Digiever DS-2105 Pro NVRs, with multiple reports linking abuse to Mirai and ShadowV2 botnet delivery. The flaw i...
Digiever DS-2105 Pro active exploitation wave (CVE-2023-52163)
Exploitation WaveAbout this happening: CVE-2023-52163 is being exploited at scale against Digiever DS-2105 Pro NVRs, with multiple reports linking abuse to Mirai and ShadowV2 botnet delivery. The flaw i...
Timeline
-
20.08.2026 03:00 1 articles · 11h ago
Zimbra releases 10.1.20 to patch CVE-2026-73570
Mitigation Patch UpdateThe Zimbra security team released version 10.1.20 for Zimbra Collaboration Suite on July 20 to fix CVE-2026-73570, a command injection flaw in the SNMP monitoring component that can let unauthenticated attackers gain remote code execution when SNMP notifications are enabled.
Show sources
- Critical Zimbra RCE flaw now actively exploited in attacks — www.bleepingcomputer.com — 20.08.2026 12:46
-
20.08.2026 03:00 2 articles · 11h ago
CERT Polska warns that CVE-2026-73570 is being exploited
Initial DisclosureCERT Polska warned that attackers are exploiting CVE-2026-73570 in Zimbra Collaboration Suite, describing it as an actively used OS command injection flaw. Shadowserver tracks over 12,100 exposed Zimbra servers online, most in Europe and Asia, and admins were told to look for Zimbra services restarting on their own and unexpected files under /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/.
Show sources
- Critical Zimbra RCE flaw now actively exploited in attacks — www.bleepingcomputer.com — 20.08.2026 12:46
- Critical Zimbra RCE flaw now actively exploited in attacks — www.bleepingcomputer.com — 20.08.2026 12:46