Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Pressure Increases for Texas to Allow Treated Drilling Waste Into Rivers and Rangeland

    August 20, 2026

    Poland’s Orlen locks in Norwegian crude supplies with Equinor amid oil market volatility

    August 20, 2026

    Israel and America Agree on Ali Shaath as Gaza’s New Leader

    August 20, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Pressure Increases for Texas to Allow Treated Drilling Waste Into Rivers and Rangeland
    • Poland’s Orlen locks in Norwegian crude supplies with Equinor amid oil market volatility
    • Israel and America Agree on Ali Shaath as Gaza’s New Leader
    • Liberia’s former Vice-President Jewel Howard-Taylor charged in drug-trafficking probe
    • 81-year-old admits German cold-case murder of US tourist in 1994
    • AI will not solve cash crisis for UK councils, warn experts
    • Burnham announces plans to clean up illegal waste dumps – UK politics live | Politics
    • How to use your TV as a PC monitor in 3 simple steps (and without buying anything)
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, August 20
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Critical Zimbra RCE flaw now actively exploited in attacks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 20, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    CERT Polska, the Polish Computer Emergency Response Team (CERT), warned that attackers have begun exploiting a critical vulnerability in Zimbra Collaboration Suite (ZCS).

    ZCS is a popular email and collaboration software suite used by hundreds of millions of people and organizations worldwide, including thousands of businesses and hundreds of government agencies.

    The Zimbra security team released version 10.1.20 on July 20 to patch the vulnerability (tracked as CVE-2026-73570), which allows unauthenticated attackers to gain remote code execution by exploiting a command injection weakness in the SNMP monitoring component when SNMP notifications are enabled.

    image

    “Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user,” it explained.

    Internet security watchdog Shadowserver now tracks over 12,100 Zimbra servers exposed online, most of them in Europe (4,382) and Asia (4,492).

    However, there is no information on how many of them are honeypots or have already been patched against the CVE-2026-73570 security flaw.

    Internet-exposed Zimbra servers
    Internet-exposed Zimbra servers (Shadowserver)

    ​Flagged as actively exploited

    On Monday, the Polish CERT team reported that threat actors are now exploiting CVE-2026-73570 in attacks.

    “The CERT Polska team reports on an actively used OS Command Injection vulnerability in the Zimbra Collaboration Suite,” it warned.

    CERT Polska also asked admins to check their logs for suspicious activity, such as the Zimbra service restarting on its own, and for files created in the /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/ folders by user zimbra over the last 30 days.

    Zimbra flaws are frequently targeted in the wild and have been used to breach many vulnerable email servers in recent years.

    For instance, Russian Winter Vivern cyber spies used a reflected XSS exploit in February 2023 to steal emails belonging to NATO-aligned individuals and organizations from Zimbra webmail portals.

    In October 2024, US and UK cyber agencies warned that APT29 hackers (tracked as Midnight Blizzard and Cozy Bear and linked to Russia’s Foreign Intelligence Service) were targeting vulnerable Zimbra servers by exploiting a security issue previously abused to steal email account credentials.

    More recently, in March, Seqrite Labs researchers also revealed that APT28 hackers (a state-backed threat group linked to Russia’s military intelligence service) were exploiting a stored cross-site scripting (XSS) vulnerability in attacks targeting Ukrainian government ZCS servers.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    actively attacks critical Exploited Flaw RCE Zimbra
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Hackers compromise 14,500 Dahua web cameras in 35-day campaign

    Microsoft says August Windows updates may cause gaming issues

    Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code

    Sakura Internet hack exposes data of up to 1.36 million accounts

    CareCloud Data Breach Impact Grows to 3.7 Million Individuals

    Rogue ransomware affiliate poses as recovery firm to steal payments

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Pressure Increases for Texas to Allow Treated Drilling Waste Into Rivers and Rangeland

    August 20, 2026

    Poland’s Orlen locks in Norwegian crude supplies with Equinor amid oil market volatility

    August 20, 2026

    Israel and America Agree on Ali Shaath as Gaza’s New Leader

    August 20, 2026

    Liberia’s former Vice-President Jewel Howard-Taylor charged in drug-trafficking probe

    August 20, 2026
    Latest Posts

    DHS Official Resigns, Citing ‘War on Immigrants’

    July 27, 2026

    Police make inquiries after Farage reports Polanski post for ‘inciting murder’ | Nigel Farage

    July 27, 2026

    A Japanese town wrestles with identity after protests over its first mosque

    July 27, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Pressure Increases for Texas to Allow Treated Drilling Waste Into Rivers and Rangeland

    August 20, 2026

    Poland’s Orlen locks in Norwegian crude supplies with Equinor amid oil market volatility

    August 20, 2026

    Israel and America Agree on Ali Shaath as Gaza’s New Leader

    August 20, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.