Zimbra Email Servers Under Active Attack: CISA Adds Critical Command Injection Flaw to Exploited Catalog

Let me ask you something: Would you leave your office front door unlocked if you knew someone was actively trying the handle?

Of course not.

But an unpatched, internet-facing email server can create a similar opening: especially now that attackers are actively exploiting a critical Zimbra Collaboration Suite vulnerability.

CISA added CVE-2026-73570 to its Known Exploited Vulnerabilities (KEV) Catalog on August 21, 2026. The catalog lists a remediation due date of August 24, 2026, under Binding Operational Directive 26-04.

That deadline directly applies to federal civilian agencies. But for your business, the message is just as important: this is not a vulnerability to put on next month’s maintenance list.

What CVE-2026-73570 means for your business

CVE-2026-73570 is an OS command injection vulnerability in Zimbra Collaboration Suite, tracked under CWE-78.

In plain English, command injection means an attacker may be able to sneak operating system instructions into data the server is processing.

Here’s the frightening part: an attacker does not need a valid Zimbra account first.

A remote, unauthenticated attacker can send specially crafted SMTP requests. When the vulnerable server processes those requests through its SNMP notification system, improper sanitization of the input may allow arbitrary operating system commands to run as the zimbra user.

That is remote code execution.

It’s like someone mailing a package to your office, except the package contains instructions that your building’s delivery system mistakenly treats as commands from the manager.

And here’s where it gets serious: an email server is not just another computer sitting in a closet.

Business owner securing an office email and network server

Why email servers are such valuable targets

Your email server may contain years of business conversations, contracts, invoices, employee information, customer records, password-reset links, and confidential attachments.

It may also be trusted by other systems.

Once an attacker gains control of a mail server, they may attempt to:

  • Read sensitive business communications
  • Steal credentials from email accounts or stored data
  • Send convincing messages from legitimate business addresses
  • Create persistence so they can return later
  • Use the server to target customers, vendors, or employees
  • Move deeper into your network

Think about it this way: your email server is often both the filing cabinet and the front desk of your business.

If someone takes over the front desk, they may learn who works there, which doors are important, and who to impersonate.

The CISA KEV listing says that ransomware use for this vulnerability is currently unknown. That does not mean the threat is harmless. It means there is not yet confirmed information that this specific flaw has been used in ransomware campaigns.

The risk remains high because the flaw is being actively exploited and may provide attackers with a foothold inside a highly trusted system.

Are you affected?

Your Zimbra environment may be exposed if all of the following conditions apply:

  • You are running a Zimbra Collaboration Suite version earlier than 10.1.20
  • The optional zimbra-snmp package is installed
  • SNMP notifications or traps are enabled through the snmp_notify parameter
  • The swatchdog service is running

CERT Polska, Poland’s national computer emergency response team, reported that the swatchdog service is enabled by default on most installations.

That means you should not assume this issue is irrelevant simply because your team did not intentionally configure every related feature.

The vulnerability was fixed in Zimbra Collaboration Suite 10.1.20, released on July 20, 2026. Zimbra described the release as containing a permanent fix for the critical SNMP vulnerability.

The fix was available roughly a month before active exploitation was confirmed. If your organization has not yet applied it, now is the time.

The exposure is larger than it may appear

Shadowserver tracks more than 12,100 Zimbra servers exposed online.

The largest concentrations reported are:

  • Europe: 4,382 exposed servers
  • Asia: 4,492 exposed servers

Those numbers do not show how many systems are patched, unpatched, or honeypots. But they demonstrate why internet-facing Zimbra servers are receiving attention from attackers.

Zimbra is also widely used. Reports describe the platform as supporting hundreds of millions of people and organizations worldwide, including thousands of businesses and hundreds of government agencies.

Popular business software attracts attention because attackers know that a successful compromise may lead to valuable information: and potentially many additional victims.

Zimbra has a history of being targeted

This is not the first time attackers have focused on Zimbra servers.

Security researchers and government agencies have previously reported activity involving:

  • Winter Vivern, which exploited a Zimbra flaw in 2023 to steal emails from NATO-aligned individuals and organizations
  • APT29, also known as Midnight Blizzard or Cozy Bear, which targeted vulnerable Zimbra servers in 2024
  • APT28, linked to Russian military intelligence, which exploited a stored cross-site scripting flaw against Ukrainian government Zimbra servers in March 2026

The lesson is simple: your email platform deserves the same attention as your firewall, remote-access tools, and cloud accounts.

It is not “just email.”

What you should do today

Start by confirming whether Zimbra is present anywhere in your environment. Check production servers, backup systems, cloud-hosted instances, and systems managed by outside vendors.

Then work through these steps.

1. Verify your Zimbra version

Confirm that every Zimbra Collaboration Suite installation is running 10.1.20 or newer.

Do not rely on an assumption that “our server was updated recently.” Verify the version directly and document the result.

If you use a hosting provider or managed service, ask for written confirmation that the affected component has been patched.

2. Check the SNMP and swatchdog configuration

Determine whether:

  • zimbra-snmp is installed
  • SNMP notifications are enabled through snmp_notify
  • swatchdog is running

If you cannot apply the update immediately, work with a qualified administrator to restrict or disable the affected notification path where appropriate.

That is a temporary risk-reduction measure: not a replacement for upgrading to the fixed version.

3. Review logs for signs of exploitation

CERT Polska recommends reviewing:

/var/log/zimbra.log

Look for unexpected service restarts or unusual entries resembling:

Service status change: <unexpected content> changed from stopped to running
Service status change: <unexpected content> changed from running to stopped

A normal service restart during maintenance is not automatically evidence of compromise. But an unexplained restart, especially alongside unfamiliar service names, command fragments, or other unusual activity, deserves immediate investigation.

4. Inspect recently created files

CERT Polska also recommends checking for files created by the zimbra user during the last 30 days in:

/opt/zimbra/jetty/webapps/
/opt/zimbra/jetty_base/webapps/
/tmp/

Pay close attention to unfamiliar scripts, web application files, executables, archives, or files that appeared outside your normal maintenance process.

Do not simply delete suspicious files. Preserve the evidence and involve an incident-response professional so you do not destroy information that could explain what happened.

IT specialist reviewing server monitoring and security activity

If you find something suspicious

If your review uncovers unexpected files, suspicious log entries, or unexplained service activity, treat the server as potentially compromised.

Your next steps should include:

  • Restricting the server’s network access where practical
  • Preserving Zimbra, operating system, and authentication logs
  • Recording suspicious file names, timestamps, and ownership
  • Reviewing administrator and user account activity
  • Rotating credentials the server could access
  • Checking for unusual outbound connections
  • Investigating whether other systems show related activity

Avoid making major changes before evidence is collected unless you need to contain an ongoing attack.

Most importantly, do not assume that upgrading the server alone proves that no one accessed it before the patch was installed.

CISA’s KEV guidance emphasizes both remediation and forensic triage for known exploited vulnerabilities. You can review the full KEV catalog entry and the BOD 26-04 remediation guidance for additional context.

What if you do not use Zimbra?

You still have an important takeaway.

Email servers are high-value targets because they combine sensitive data, trusted identities, and connections to the rest of your business. Whether you use Zimbra, Microsoft Exchange, a hosted platform, or another mail system, you should know:

  • Which version you are running
  • Who is responsible for patching it
  • Whether it is exposed directly to the internet
  • How logs are reviewed
  • How quickly you can isolate it during an incident
  • Whether backups are protected and recoverable

A locked office is only useful if you know which doors exist.

Need help checking your exposure?

This issue is urgent, but you do not have to investigate it alone.

Platinum Web Services helps small businesses review systems, apply security updates, strengthen network access controls, and respond when something looks wrong. Our Security Advisory Hub provides additional guidance on active threats affecting businesses like yours.

We provide support 24/7, including for urgent IT and security emergencies.

If you would like help verifying your Zimbra version, reviewing your exposure, or checking for signs of compromise, contact Platinum Web Services.

The safest email server is not the one you hope is protected. It is the one you have verified, patched, monitored, and prepared to defend.

Category: CISA Advisories

0 Comments

Submit a Comment

Your email address will not be published. Required fields are marked *