CVE-2026-73570: Critical Zimbra Collaboration Suite RCE Actively Exploited
CVE-2026-73570 is a critical unauthenticated remote code execution vulnerability affecting Zimbra Collaboration Suite, confirmed by CERT Polska to be actively exploited in the wild. The flaw allows unauthenticated attackers to execute arbitrary shell commands with the privileges of the zimbra user. This vulnerability represents one of the most significant Zimbra security issues in recent years, given that it can be exploited without any authentication credentials.
Vulnerability Details
The flaw, tracked as CVE-2026-73570, is a command injection vulnerability in the SNMP monitoring component of Zimbra Collaboration Suite. The vulnerability affects instances that have the SNMP trap service enabled via the snmp_notify parameter and the swatchdog service running (enabled by default on most installations). The technical root cause is a sanitization failure in the SNMP monitoring component that fails to properly validate input before passing it to the shell. Attackers can inject arbitrary commands through SNMP trap notifications, which are then processed by the swatchdog service. The vulnerability was initially patched in Zimbra version 10.1.20 released on 20 July 2026, but CERT Polska confirmed active exploitation began approximately 28 days after the patch release, indicating that many administrators delayed updating their systems. The exploit chain requires two conditions to be met: the optional zimbra-snmp package must be installed, and the swatchdog service must be running, which is the default configuration on the majority of Zimbra deployments.
Impact Assessment
The vulnerability poses significant risk to organizations worldwide for several reasons. First, it allows unauthenticated remote code execution, meaning attackers do not need valid user credentials to compromise the system. Second, the vulnerable service (swatchdog) is enabled by default on most Zimbra installations, creating a wide attack surface. Third, over 12,100 Zimbra servers are reachable from the internet according to Shadowserver's statistics, split roughly between Europe (4,382) and Asia (4,492). These figures don't distinguish between patched and unpatched instances, or between production servers and honeypots, so the real attack surface is smaller but still substantial. The impact includes complete system compromise, where attackers can read arbitrary files, install malware, pivot to other systems in the network, and exfiltrate sensitive data such as emails and attachments. Organizations in sectors targeted by state-backed threat actors should treat unpatched Zimbra servers as a high priority target, as the combination of unauthenticated access and default enabled services makes this flaw particularly attractive for rapid exploitation.
Affected Systems
Organizations running Zimbra Collaboration Suite versions prior to 10.1.20 are affected by this vulnerability. The attack surface exists when the optional zimbra-snmp package is installed and SNMP notifications are active, but the swatchdog service runs by default on most installations. Even Zimbra deployments that do not explicitly enable SNMP may be vulnerable if the swatchdog service is running, as it may have been started as part of the initial setup. The vulnerability affects all supported Zimbra Collaboration Suite versions before 10.1.20, including both the open-source Zimbra Community Edition and the commercial Network Edition. Organizations should inventory their Zimbra servers and prioritize updating systems that are exposed to the internet.
Mitigation & Patching
Immediate actions (within 24-48 hours):
- Update Zimbra Collaboration Suite to version 10.1.20 or later via the official Zimbra admin console or command-line interface. The update patches the sanitization failure in the SNMP monitoring component.
- If immediate updating is not possible, disable the SNMP trap service if it is not required for monitoring operations. This can be done via the Zimbra admin interface or by removing the zimbra-snmp package.
- Monitor Zimbra logs at /var/log/zimbra.log for suspicious activity, specifically looking for service status change entries where malicious payloads transition from stopped to running and back.
- Check for any unauthorized changes to Zimbra configuration or the creation of unexpected files in the Zimbra web application directories.
Long-term security improvements:
- Regularly check for Zimbra security updates and apply them promptly (within the organization's patch management policy)
- Disable unnecessary services and packages, including the zimbra-snmp package if SNMP monitoring is not used
- Implement network segmentation to limit internet exposure of Zimbra servers
- Configure monitoring and alerting for anomalous Zimbra log activity
- Conduct regular security assessments of collaboration and communication systems
Detection
Administrators should perform the following checks to determine if their Zimbra servers have been exploited:
-
Log analysis: Check /var/log/zimbra.log for service status change entries where the payload transitions from stopped to running and back. This pattern indicates that a command was executed as a service, which is the signature of a malicious command injection.
-
File inspection: Look for files created by the zimbra user in the last 30 days in these directories:
- /opt/zimbra/jetty/webapps/
- /opt/zimbra/jetty_base/webapps/
- /tmp/
Web shells dropped in these directories would give persistent access after the initial command injection. Any unknown PHP, JavaScript, or other executable files in these locations should be investigated immediately.
-
Network monitoring: Monitor inbound SNMP trap connections to Zimbra servers, especially from unexpected source IPs. While SNMP is typically used for legitimate monitoring, unexpected trap requests could indicate active exploitation attempts.
-
Integrity checking: Compare current Zimbra file installations against known good baselines. Look for modified or additional files in the Zimbra directory structure.
Frequently Asked Questions
Q: Who is affected by CVE-2026-73570? A: Organizations running Zimbra Collaboration Suite versions before 10.1.20 with the SNMP package installed and swatchdog service running. Even deployments that do not explicitly enable SNMP may be vulnerable if swatchdog is running, as it may have been started during initial setup.
Q: How was the vulnerability discovered? A: CERT Polska confirmed active exploitation and published an advisory with detailed technical information. The 28-day gap between the patch release and confirmed exploitation suggests that threat actors were actively searching for unpatched systems.
Q: Is CVE-2026-73570 in CISA's Known Exploited Vulnerabilities catalog? A: Not yet, but given the active exploitation and the number of exposed servers, it is likely to be added soon. Organizations should not wait for official cataloging before applying the patch.
Q: What is the CVSS score for CVE-2026-73570? A: The CVSS score has not been officially published, but the vulnerability is described as critical unauthenticated RCE, which typically scores 9.0-10.0 on the CVSS v3 scale. The combination of unauthenticated access, remote code execution, and default-enabled attack surface warrants a maximum score.
Q: Can I detect if my server has been exploited? A: Yes. Check /var/log/zimbra.log for unusual service status changes, look for new files in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/ created by the zimbra user in the last 30 days. Web shells dropped in these directories would give persistent access after the initial command injection.
Q: Should I disable SNMP completely? A: If you do not use SNMP monitoring, disabling the zimbra-snmp package is recommended as a precaution. If SNMP monitoring is required, ensure that the system is updated to version 10.1.20 or later immediately, as the vulnerability is actively exploited in the wild.
Q: How does this vulnerability compare to other Zimbra flaws? A: CVE-2026-73570 is particularly significant because it allows unauthenticated remote code execution, unlike many previous Zimbra vulnerabilities that required some level of authentication. The default-enabled swatchdog service and the wide exposure of Zimbra servers on the internet make this flaw especially dangerous compared to earlier issues.
Key Takeaways
- CVE-2026-73570 is a critical unauthenticated RCE in Zimbra Collaboration Suite affecting versions before 10.1.20
- The vulnerability exploits the SNMP monitoring component via the swatchdog service, which is enabled by default
- Over 12,100 Zimbra servers are exposed on the internet, creating a large attack surface
- The flaw allows unauthenticated attackers to execute arbitrary shell commands with zimbra user privileges
- Update to version 10.1.20 or later immediately and monitor logs for signs of exploitation
- Organizations should inventory their Zimbra servers and prioritize internet-exposed systems for patching
Sources:
- CERT Polska advisory: https://moje.cert.pl/komunikaty/2026/145/aktywnie-wykorzystywana-podatnosc-w-zimbra-collaboration-suite/
- Security Affairs article: https://securityaffairs.com/197610/security/polands-cert-warns-of-active-exploitation-of-critical-zimbra-collaboration-suite-flaw.html
- CVE Record: https://www.cve.org/CVERecord?id=CVE-2026-73570
- Shadowserver statistics: https://dashboard.shadowserver.org/statistics/iot-devices/time-series/
- Zimbra Security Advisory: https://zimbra.com/security-advisories/
Automated Transmission
This entry was synthesized and populated dynamically using native API integrations.