Find notable cyber news and cases, enriched with sources, timelines, and signals.

Zimbra Collaboration Suite actively exploited command injection RCE (CVE-2026-73570)

Vulnerability
First reported
Last updated
Happening score
H score 33
1 unique sources, 1 articles

Summary

Hide ▲

CVE-2026-73570 in Zimbra Collaboration Suite (ZCS) is now actively exploited, giving attackers unauthenticated remote code execution against exposed servers. The flaw is a command injection issue in the SNMP monitoring component when SNMP notifications are enabled. Zimbra 10.1.20 was released on July 20 to patch the vulnerability, and exposed deployments remain a live target.

Related Happenings

APT28 Operation GhostMail Zimbra phishing campaign targeting Ukrainian government entities

Campaign
H score37 First: 19.03.2026 16:55 Last: 19.03.2026 16:55 Sources 1

About this happening: APT28’s Operation GhostMail is actively targeting Ukrainian government entities through a phishing chain that exploits CVE-2025-66376 in Zimbra Collaboration Sui...

CISA patch guidance for Zimbra and SharePoint flaws

Advisory/Mitigation
H score56 First: 19.03.2026 08:05 Last: 19.03.2026 08:05 Sources 1

About this happening: CISA, NSA, and partner agencies issued a joint advisory on CVE-2025-66376, a stored XSS flaw in Zimbra Collaboration Classic UI that lets a crafted email r...

CISA BOD 22-01 Zimbra patch order

Public Sector Action
H score34 First: 18.03.2026 21:57 Last: 18.03.2026 21:57 Sources 1

About this happening: CISA ordered Federal Civilian Executive Branch agencies to secure Zimbra Collaboration Suite (ZCS) servers against CVE-2025-66376, an actively exploited flaw t...

Digiever DS-2105 Pro active exploitation wave (CVE-2023-52163)

Exploitation Wave
H score39 First: 25.12.2025 10:07 Last: 25.12.2025 10:07 Sources 1

About this happening: CVE-2023-52163 is being exploited at scale against Digiever DS-2105 Pro NVRs, with multiple reports linking abuse to Mirai and ShadowV2 botnet delivery. The flaw i...

Timeline

  1. 20.08.2026 03:00 1 articles · 11h ago

    Zimbra releases 10.1.20 to patch CVE-2026-73570

    Mitigation Patch Update

    The Zimbra security team released version 10.1.20 for Zimbra Collaboration Suite on July 20 to fix CVE-2026-73570, a command injection flaw in the SNMP monitoring component that can let unauthenticated attackers gain remote code execution when SNMP notifications are enabled.

    Show sources
  2. 20.08.2026 03:00 2 articles · 11h ago

    CERT Polska warns that CVE-2026-73570 is being exploited

    Initial Disclosure

    CERT Polska warned that attackers are exploiting CVE-2026-73570 in Zimbra Collaboration Suite, describing it as an actively used OS command injection flaw. Shadowserver tracks over 12,100 exposed Zimbra servers online, most in Europe and Asia, and admins were told to look for Zimbra services restarting on their own and unexpected files under /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/.

    Show sources