{"id":863413,"date":"2026-08-21T17:10:32","date_gmt":"2026-08-21T17:10:32","guid":{"rendered":"https:\/\/www.newsbeep.com\/au\/863413\/"},"modified":"2026-08-21T17:10:32","modified_gmt":"2026-08-21T17:10:32","slug":"polands-cert-warns-of-active-exploitation-of-critical-zimbra-collaboration-suite-flaw","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/au\/863413\/","title":{"rendered":"Poland&#8217;s CERT Warns of Active Exploitation of Critical Zimbra Collaboration Suite Flaw"},"content":{"rendered":"<p>\n\t\t\t\t\t\t\tPoland\u2019s CERT Warns of Active Exploitation of Critical Zimbra Collaboration Suite Flaw\n\t\t\t\t\t\t<\/p>\n<p>\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/securityaffairs.com\/wp-content\/themes\/security_affairs\/images\/user-icon.svg\" alt=\"\"\/> <a href=\"https:\/\/securityaffairs.com\/author\/paganinip\" rel=\"nofollow noopener\" target=\"_blank\">Pierluigi Paganini<\/a><br \/>\n\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/securityaffairs.com\/wp-content\/themes\/security_affairs\/images\/clock-icon.svg\" alt=\"\"\/> August 21, 2026<\/p>\n<p>\t\t\t\t\t\t<img decoding=\"async\" class=\"img-fluid mb-4\" src=\"https:\/\/www.newsbeep.com\/au\/wp-content\/uploads\/2026\/08\/zimbra.png\" alt=\"\"\/><\/p>\n<p>CERT Polska confirmed active exploitation of CVE-2026-73570, a critical unauthenticated RCE in Zimbra Collaboration Suite patched on July 20.<\/p>\n<p class=\"wp-block-paragraph\">CERT Polska, Poland\u2019s national computer emergency response team, confirmed this week that threat actors are actively exploiting a critical vulnerability in Zimbra Collaboration Suite tracked as CVE-2026-73570. The flaw allows unauthenticated remote code execution and was patched less than a month ago.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe CERT Polska team informs about an actively exploited OS Command Injection vulnerability in Zimbra Collaboration Suite.\u201d reads the <a href=\"https:\/\/moje.cert.pl\/komunikaty\/2026\/145\/aktywnie-wykorzystywana-podatnosc-w-zimbra-collaboration-suite\/#\" rel=\"nofollow noopener\" target=\"_blank\">advisory<\/a> published by CERT Polska. \u201cThe vulnerability, identified as\u00a0<a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-73570\" rel=\"nofollow noopener\" target=\"_blank\">CVE-2026-73570<\/a>\u00a0, allows an unauthenticated attacker to execute arbitrary shell commands with the privileges of\u00a0the zimbra\u00a0user . The vulnerability affects instances that have the SNMP trap service enabled via the\u00a0\u00a0snmp_notify\u00a0parameter \u00a0and the swatchdog service running (enabled by default).\u201d<\/p>\n<p class=\"wp-block-paragraph\">The vulnerability affects systems with SNMP trap notifications enabled and the swatchdog service running, which is enabled by default. The technical root cause is a sanitization failure in the SNMP monitoring component. <\/p>\n<p class=\"wp-block-paragraph\">Zimbra released version 10.1.20 on 20 July 2026 to address the issue. The fix came 28 days before active exploitation was confirmed, which is not a wide window, but apparently wide enough.<\/p>\n<p class=\"wp-block-paragraph\">The attack surface only exists when the optional zimbra-snmp package is installed and SNMP notifications are active, but swatchdog, the service that processes those notifications, is running by default on most installations.<\/p>\n<p class=\"wp-block-paragraph\">Below are recommendations by CERT Polska:<\/p>\n<p class=\"wp-block-paragraph\">\u201cDue to the ongoing campaign exploiting this vulnerability, we recommend:<\/p>\n<p>verifying Zimbra logs\u00a0\/var\/log\/zimbra.log\u00a0for the following entries:<\/p>\n<p>Service status change:  changed from stopped to running<br \/>\nService status change:  changed from running to stopped<\/p>\n<p>verification of files created by user zimbra\u00a0in the last 30 days\u00a0in the following directories:<\/p>\n<p>\/opt\/zimbra\/jetty\/webapps\/<br \/>\n\/opt\/zimbra\/jetty_base\/webapps\/<br \/>\n\/tmp\/<\/p>\n<p class=\"wp-block-paragraph\">If you discover any signs of potential exploitation of this vulnerability, please contact our team immediately.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The exposure numbers aren\u2019t reassuring. Shadowserver <a href=\"https:\/\/dashboard.shadowserver.org\/statistics\/iot-devices\/time-series\/?date_range=other_range&amp;d1=2026-07-01&amp;d2=2026-08-19&amp;vendor=synacor&amp;model=zimbra+collaboration+suite&amp;dataset=count&amp;limit=100&amp;group_by=geo&amp;stacking=stacked\" rel=\"nofollow noopener\" target=\"_blank\">currently tracks<\/a> over 12,100 Zimbra servers reachable from the Internet, split roughly between Europe (4,382) and Asia (4,492). That figure doesn\u2019t distinguish between patched and unpatched instances, or between production servers and honeypots, so the real attack surface is smaller, but nobody knows by how much.<\/p>\n<p class=\"wp-block-paragraph\">CERT Polska published indicators of compromise alongside the advisory and gave administrators specific places to look. The team recommends checking \/var\/log\/zimbra.log for service status change entries where the payload transitions from stopped to running and back, which is the signature of a malicious command being executed as a service. Admins should also check whether any files were created in \/opt\/zimbra\/jetty\/webapps\/, \/opt\/zimbra\/jetty_base\/webapps\/, or \/tmp\/ by the zimbra user in the last 30 days. Web shells dropped into those directories would give persistent access after the initial command injection.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-73570 isn\u2019t yet in CISA\u2019s Known Exploited Vulnerabilities catalog, which currently lists 18 Zimbra Collaboration Suite entries, four of them added this year. The absence doesn\u2019t mean the threat is lower; it means the catalog hasn\u2019t caught up yet.<\/p>\n<p class=\"wp-block-paragraph\">Zimbra solutions have been targeted by nation-state actors for years. Russian espionage group <a href=\"https:\/\/securityaffairs.com\/153030\/apt\/winter-vivern-0day-roundcube.html\" data-type=\"post\" data-id=\"153030\" rel=\"nofollow noopener\" target=\"_blank\">Winter Vivern<\/a> exploited a reflected XSS flaw in February 2023 to steal emails from NATO-aligned organizations through Zimbra webmail portals. In October 2024, US and UK agencies warned that <a href=\"https:\/\/securityaffairs.com\/169708\/apt\/apt29-target-zimbra-and-jetbrains-teamcity.html\" data-type=\"post\" data-id=\"169708\" rel=\"nofollow noopener\" target=\"_blank\">APT29<\/a>, linked to Russia\u2019s Foreign Intelligence Service, was targeting vulnerable Zimbra servers via a credential-stealing flaw. Most recently, in March 2026, Seqrite Labs researchers documented APT28, tied to Russian military intelligence, exploiting a stored XSS vulnerability against Ukrainian government Zimbra deployments.<\/p>\n<p class=\"wp-block-paragraph\">Organizations in sectors targeted by Russian or Chinese state-backed groups should treat unpatched Zimbra servers as a high priority. CVE-2026-73570 is especially risky because attackers can exploit it without authentication, the vulnerable service is enabled by default, and many Zimbra servers are exposed online. These conditions make the flaw an attractive target for rapid exploitation.<\/p>\n<p class=\"wp-block-paragraph\">Follow me on Twitter:\u00a0<a href=\"https:\/\/twitter.com\/securityaffairs\" rel=\"nofollow noopener\" target=\"_blank\">@securityaffairs<\/a>\u00a0and\u00a0<a href=\"https:\/\/www.facebook.com\/sec.affairs\" rel=\"nofollow noopener\" target=\"_blank\">Facebook<\/a>\u00a0and\u00a0<a href=\"https:\/\/infosec.exchange\/@securityaffairs\" rel=\"nofollow noopener\" target=\"_blank\">Mastodon<\/a><\/p>\n<p class=\"wp-block-paragraph\"><a href=\"http:\/\/www.linkedin.com\/pub\/pierluigi-paganini\/b\/742\/559\" rel=\"nofollow noopener\" target=\"_blank\">Pierluigi\u00a0Paganini<\/a><\/p>\n<p class=\"wp-block-paragraph\">(<a href=\"http:\/\/securityaffairs.co\/wordpress\/\" rel=\"nofollow noopener\" target=\"_blank\">SecurityAffairs<\/a>\u00a0\u2013\u00a0hacking,\u00a0Zimbra Collaboration Suite)<\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"Poland\u2019s CERT Warns of Active Exploitation of Critical Zimbra Collaboration Suite Flaw Pierluigi Paganini August 21, 2026 CERT&hellip;\n","protected":false},"author":2,"featured_media":863414,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[64,63,432583,8886,192597,418180,429676,429678,432584,429680,429681,105,432585],"class_list":["post-863413","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-au","tag-australia","tag-cve-2026-73570","tag-hacking","tag-hacking-news","tag-information-security-news","tag-it-information-security","tag-pierluigi-paganini","tag-poland-cert","tag-security-affairs","tag-security-news","tag-technology","tag-zimbra-collaboration-suite"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/863413","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/comments?post=863413"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/863413\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media\/863414"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media?parent=863413"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/categories?post=863413"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/tags?post=863413"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}