CISA orders immediate patching of actively exploited Zimbra vulnerability

0
65
Actively exploited Zimbra flaw puts thousands of servers at risk Credit: Bleeping Computer
Actively exploited Zimbra flaw puts thousands of servers at risk Credit: Bleeping Computer

A critical vulnerability in Zimbra Collaboration Suite is being actively exploited, prompting the US Cybersecurity and Infrastructure Security Agency (CISA) to order federal agencies to secure affected systems within 3 days.

Tracked as CVE-2026-73570, the flaw affects Zimbra Collaboration Suite (ZCS) and can allow unauthenticated attackers to execute arbitrary operating system commands remotely. The vulnerability is caused by improper input sanitisation in the SNMP monitoring component when SNMP notifications are enabled.

Zimbra addressed the issue in version 10.1.20, released on July 20. The flaw can be exploited through specially crafted SMTP requests, potentially allowing attackers to execute commands with the privileges of the Zimbra user.

The warning follows an alert from Poland’s Computer Emergency Response Team, which reported that the vulnerability was being exploited in the wild.

More than 12,000 Zimbra servers are currently exposed to the internet, according to threat monitoring data. It remains unclear how many are honeypots or have already been secured against attacks exploiting the flaw.

Security monitoring also identified more than 270 compromised Zimbra Collaboration Suite instances while searching for indicators associated with CVE-2026-73570 exploitation.

CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on August 21 and directed US Federal Civilian Executive Branch agencies to patch their systems by August 24.

Although details of the attacks have not been publicly disclosed, security teams have been advised to examine logs for suspicious activity. This includes unexpected Zimbra service restarts and files created by the Zimbra user in the /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/ and /tmp/ directories during the previous 30 days.

Zimbra is widely used by organisations and individuals globally, including hundreds of government agencies and thousands of businesses, making vulnerable installations an attractive target.

The platform has faced repeated exploitation in recent years. In March, researchers reported that APT28, a Russia-linked state-sponsored group, was exploiting a stored XSS flaw against Ukrainian government Zimbra servers.

In October 2024, US and UK cyber agencies warned that APT29, also known as Midnight Blizzard and Cozy Bear, was targeting Zimbra servers using a vulnerability linked to credential theft. Russian-linked Winter Vivern hackers have also exploited a reflected XSS flaw in Zimbra webmail portals to steal emails from NATO-aligned organisations and individuals.

Also read: Viksit Workforce for a Viksit Bharat

Do Follow: The Mainstream LinkedIn | The Mainstream Facebook | The Mainstream Youtube | The Mainstream Twitter

About us:

The Mainstream is a premier platform delivering the latest updates and informed perspectives across the technology business and cyber landscape. Built on research-driven, thought leadership and original intellectual property, The Mainstream also curates summits & conferences that convene decision makers to explore how technology reshapes industries and leadership. With a growing presence in India and globally across the Middle East, Africa, ASEAN, the USA, the UK and Australia, The Mainstream carries a vision to bring the latest happenings and insights to 8.2 billion people and to place technology at the centre of conversation for leaders navigating the future.