Hackers Target Zimbra Servers in Active Exploitation Campaign via CVE-2026-73570 SNMP Command Injection — Threadlinqs Intelligence
As of 2026-08-25, Hackers Target Zimbra Servers in Active Exploitation Campaign via CVE-2026-73570 SNMP Command Injection is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 31 indicators of compromise.
Threat ID: TL-2026-2082 · Severity: CRITICAL · CVSS: 8.9 · Status: ACTIVE · Category: VULNERABILITY
Updated: 2026-08-25 · 4 updates · revalidated 4× · latest source
An unauthenticated remote code execution vulnerability (CVE-2026-73570, CVSS 8.9) in Zimbra Collaboration Suite (ZCS) prior to version 10.1.20 is being actively exploited in the wild. The OS command
CVE-2026-73570 is a high-severity (CVSS 8.9) OS command injection vulnerability in Zimbra Collaboration Suite (ZCS) that enables unauthenticated remote code execution. The flaw exists in the optional zimbra-snmp package when SNMP trap notifications are enabled and the swatchdog service is running (swatchdog is enabled by default in Zimbra deployments). Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests to a vulnerable Zimbra server that, when processed through the SNMP notification subsystem, result in the execution of arbitrary operating system commands under the privileges of the zimbra user account. The vulnerability was fixed by Zimbra in version 10.1.20 ("Daffodil"), released on July 20, 2026, following a security advisory initially published on June 26, 2026.
CERT Polska issued advisory #145/2026 on August 17, 2026, warning that threat actors are actively exploiting CVE-2026-73570 in an ongoing campaign. ENISA confirmed exploitation in its KEV catalog on August 18, noting exploitation waves since the beginning of August. CERT-FR followed with advisory CERTFR-2026-AVI-1041 on August 19, and CCB Belgium issued an urgent warning the same day. Public reporting from SecurityWeek, BleepingComputer, and The Hacker News on August 20, 2026, brought the campaign to broader attention.
The Shadowserver Foundation tracked over 12,100 internet-exposed Zimbra servers, with the largest concentrations in Europe (4,382 servers) and Asia (4,492 servers), representing a substantial attack surface. The remaining servers were distributed across North America and other regions, though Shadowserver noted uncertainty about how many were honeypots or had already been patched.
Once attackers achieve command execution as the zimbra user, they can deploy web shells in Zimbra's Jetty web application directories (/opt/zimbra/jetty/webapps/ and /opt/zimbra/jetty_base/webapps/), drop staging files in /tmp/, access and exfiltrate email account data, harvest credentials from mailboxes and stored configurations, modify server-side settings, establish persistence mechanisms, and use the compromised mail server as a pivot point for lateral movement within the target network. The compromised Zimbra server runs email for the entire organization, making it a high-value target for credential theft, intelligence gathering, and further network penetration.
CERT Polska recommended specific IOC checks: inspect /var/log/zimbra.log for anomalous service status change entries containing attacker payloads, and audit files created by the zimbra user within the last 30 days under the Jetty webapps directories and /tmp/. No public proof-of-concept exploit code has been released, and no specific threat actor has been attributed to this campaign at the time of reporting. Zimbra vulnerabilities have historically been exploited by Russian state-sponsored groups (APT28, APT29, Winter Vivern, LAUNDRY BEAR) and Chinese state-sponsored actors, but the attribution for CVE-2026-73570 exploitation remains unknown.
Target sectors: government administration, military, diplomatic, education, enterprise
Target regions: Europe, Asia, North America
Timeline
- Zimbra initially discloses an SNMP command injection vulnerability in its security advisory, before a CVE is assigned
- Zimbra releases version 10.1.20 (Daffodil) fixing the SNMP command injection vulnerability along with 8 other security issues including multiple XSS flaws, CVE-2026-50055 (mail forwarding bypass), CVE-2026-50054 (mailbox delegation authorization), CVE-2026-10631 (EWS access control), and an SSRF in Nextcloud integration
- ENISA reports exploitation waves beginning in early August 2026, approximately 10 days after the patch was released
- CVE-2026-73570 is formally published in NVD with a CVSS 8.9 (HIGH) rating; GitHub Advisory Database updated with GHSA-jqh7-pchh-v74j
- CERT Polska issues advisory #145/2026 warning of an active exploitation campaign targeting CVE-2026-73570, providing specific IOC patterns and file paths for forensic analysis
- ENISA confirms the vulnerability as exploited in its KEV catalog (entry ID: c0bf679d-88c4-4a63-9674-a7bec42990c9), noting exploitation waves since early August 2026
- CERT-FR issues advisory CERTFR-2026-AVI-1041 confirming active exploitation; CCB Belgium issues urgent warning urging immediate patching of Zimbra servers
- SecurityWeek, BleepingComputer, The Hacker News, and CybersecurityNews publish reports on the active exploitation campaign; Shadowserver reports 12,100+ exposed Zimbra servers online
- Shadowserver Foundation identifies 155 compromised internet-facing Zimbra instances, the first confirmed-compromise count for this campaign.
- CISA adds CVE-2026-73570 to its Known Exploited Vulnerabilities (KEV) catalog, mandating remediation under Binding Operational Directive (BOD) 26-04 by 2026-08-24 (3-day deadline).
- Security Affairs publishes coverage of the CISA KEV catalog addition for CVE-2026-73570, the report that triggered this revalidation.
- Shadowserver scan data shows the compromised internet-facing ZCS instance count rising past 270.
Update History
- 2026-08-25 — CVE-2026-73570: Unauthenticated RCE in Zimbra SNMP Component Exploited to Breach 270+ Servers: What changed No change to severity_level, exploitability, status, cvss_score, or attribution fields -- all match the existing record. The report's compromise counts (274+, 8,200 unpatched), CISA KEV/BOD deadline, and CERT Polska guidance du
- 2026-08-25 — CVE-2026-73570: Zimbra Collaboration Suite SNMP Command Injection Actively Exploited, 274+ Instances Compromised: What changed No field escalation — severity (CRITICAL), exploitability (ACTIVE), and status (ACTIVE) were already at their ceiling. The material change is confirmed-compromise scale: Shadowserver counted 155 compromised instances on 2026-08
- 2026-08-22 — CISA Adds Zimbra Collaboration Suite (ZCS) SNMP Command Injection Flaw CVE-2026-73570 to KEV Catalog: What changed No escalation — severity remains CRITICAL, exploitability ACTIVE, status ACTIVE, CVSS 8.9, attribution LOW, matching the existing record. Report adds an EPSS score (0.54%, 43rd percentile), names NASK/Poland as CERT Polska's pa
- 2026-08-21 — CVE-2026-73570: OS Command Injection in Zimbra Collaboration Suite SNMP Notification Processing — Active Exploitation: What changed CISA added CVE-2026-73570 to its KEV catalog on 2026-08-21, mandating remediation under BOD 26-04 by 2026-08-24; severity escalated HIGH → CRITICAL reflecting the mandatory-remediation KEV listing and continued active exploitat
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 31 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-73570, T1190, T1059, T1505, T1543, T1078, T1003, T1087, T1021, T1114, T1560