HomeSecurityZimbra vulnerability exploited for remote code execution

Zimbra vulnerability exploited for remote code execution

A new security warning for Zimbra Collaboration comes from the Polish Computer Emergency Response Team (CERT Polska). The organization has identified indications that a serious vulnerability is already being exploited in real attacks. The issue has now been fixed by Zimbra, however organizations that have not installed the necessary update remain exposed.

Zimbra vulnerability exploit

The vulnerability has been registered as CVE-2026-73570 and has a CVSS score of 8.9, which makes it a very serious security vulnerability. The problem is related to command injection and could, under certain conditions, allow a remote and unauthenticated attacker to execute arbitrary commands on the server's operating system.

See also: Zimbra zero-click exploit: Russian group steals emails and 2FA codes via CVE-2025-66376

How can the attack be carried out?

According to the vulnerability description in NIST's National Vulnerability Database , the issue affects versions of Zimbra Collaboration prior to 10.1.20 , when the optional zimbra-snmp package is installed and the relevant SNMP notifications are enabled .

The key vulnerability lies in the way the system processes data that has not been adequately checked. An attacker could attempt to input specially crafted data, which could then be treated as operating system commands.

What is particularly worrying is that no prior authentication is required. If the attack is successful, the commands are executed with the privileges of the Zimbra user. This could be a starting point for further server compromise, malware installation, or access to email data.

Information is the most important protection measure

Zimbra addressed the issue by releasing version 10.1.20, which includes the relevant fix. For system administrators, installing the update is now a priority, especially on infrastructures that are accessible from the internet.

However, installing a patch should not be considered the end of the process. Since the vulnerability appears to be actively being exploited, organizations should also consider the possibility of a prior breach of their systems.

What administrators should check

CERT Polska recommends that security administrators examine the /var/log/zimbra.log, looking for unusual Zimbra service restarts. It also recommends checking for unknown or suspicious files created in the last 30 days in the following directories:

  • /opt/zimbra/jetty/webapps/
  • /opt/zimbra/jetty_base/webapps/
  • /tmp/

This process can help identify signs of compromise, especially when combined with checking logs, network connections, and user accounts.

See also: Russian hackers target Ukraine via Zimbra vulnerability

Zimbra - SecNews.gr

Zimbra remains an attractive target

This particular case is not an isolated incident. Zimbra servers have repeatedly been targeted by cybercriminals, as they function as central points for managing corporate and government correspondence.

Just last month, US authorities revealed evidence of a phishing attributed to Laundry Bear, a group with ties to Russia. The campaign targeted Zimbra servers of government and commercial organizations in the West since at least July 2025.

See also: GitLab RCE PoC: Exploit in self-managed GitLab via Jupyter notebook diff (Oj)

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The attackers then exploited CVE-2025-66376, a Stored XSS vulnerability in Zimbra's Classic UI, to install the malicious JavaScript payload ZimReaper, with the aim of intercepting emails and other sensitive information.

Article Image: Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets

Another lesson for organizations

The new active exploit highlights that email servers need constant monitoring, not just occasional updates. Promptly installing patches, disabling unnecessary services, limiting internet exposure, monitoring logs, and having an incident response plan can significantly limit the consequences of an attack.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS