CERT Polska has warned that threat actors are actively exploiting CVE-2026-73570, a critical OS command-injection vulnerability in Zimbra Collaboration Suite that allows remote, unauthenticated attackers to execute arbitrary shell commands as the zimbra user.
The vulnerability affects Zimbra installations in which the SNMP trap service is enabled via the snmp_notify parameter and the swatchdog service is running.
Since swatchdog is enabled by default, exposed servers with SNMP notifications configured may face a heightened risk of compromise. Successful exploitation could give attackers a foothold on vulnerable mail servers without requiring valid credentials.
From there, attackers may execute malicious commands, create or modify files, deploy web shells, steal email data, establish persistence, or use the compromised server to target other systems within an organization.
Zimbra Collaboration Suite Vulnerability Exploited
CERT Polska said the issue has already been observed in an ongoing exploitation campaign. Organizations using Zimbra Collaboration Suite should therefore treat the vulnerability as an immediate incident-response and patch-management priority rather than a routine software update.
Zimbra fixed CVE-2026-73570 in version 10.1.20. Administrators should verify the installed Zimbra version and upgrade affected systems to a patched release as soon as possible.
Systems that cannot be updated immediately should be reviewed for whether SNMP trap functionality is necessary and whether the snmp_notify configuration is enabled.
Security teams should also inspect Zimbra logs for suspicious changes in service status. Relevant entries may show an unfamiliar service or command payload changing from “stopped” to “running,” or from “running” to “stopped.”
These events may indicate that an attacker used the vulnerable component to trigger malicious commands through the swatchdog service.
Administrators should specifically review /var/log/zimbra.log for unexpected “Service status change” records. Any service names, command strings, or payloads that do not match normal operational activity should be investigated.
CERT Polska also recommends checking for recently created files owned by the zimbra user. The highest-priority directories include /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/.
Web application directories are especially important because attackers often place JSP-based web shells or other malicious application files there to maintain remote access after initial exploitation.
Files created or modified in the past 30 days should be reviewed for unusual names, obfuscated code, unexpected archive files, executable scripts, unauthorized JSP files, and outbound network activity associated with the Zimbra server.
If signs of compromise are found, organizations should isolate the affected server, preserve logs and suspicious files for forensic analysis, rotate potentially exposed credentials, and investigate connected systems for lateral movement. CERT Polska has requested that evidence of suspected exploitation be reported to its incident-response team.
The active exploitation of CVE-2026-73570 highlights the continued targeting of internet-facing email infrastructure. Prompt patching, log review, and web-shell hunting are essential to reduce the risk of a full Zimbra server compromise.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

