Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
5SEP

CERT Polska finds Zimbra flaw under attack

2 min read
12:09UTC

Poland's national CERT reported on 17 August that attackers were exploiting a command-injection flaw in Zimbra Collaboration Suite. The way in is a monitoring feature, not the webmail.

TechnologyAssessed
Key takeaway

A monitoring option, not the webmail itself, is the route attackers take into exposed Zimbra servers.

CERT Polska, Poland's national computer emergency response team, reported on 17 August that CVE-2026-73570 was being exploited against Zimbra Collaboration Suite 1. The flaw lets an attacker who has not logged in run the operating system's own commands as the Zimbra user, the account the mail platform itself runs under, wherever Simple Network Management Protocol notification and swatchdog are switched on. SNMP is the protocol network kit uses to report its own health; swatchdog watches log files and fires an action when a pattern appears.

It scores 8.9, and Zimbra fixed it in release 10.1.20 2. Neither of those two features is mail. Both are the kind of operational plumbing an administrator switches on once during commissioning, and a shop that inventories its mail platform by version number will not have recorded whether either is enabled.

This has nothing in common with the zero-click webmail chain that fifteen agencies wrote up in July, which fired when a target merely previewed a message . That advisory told administrators to patch the appliance. This one asks a different question, namely which optional components are running on it, and the answer is not in any patch level.

The Canadian Centre for Cyber Security issued its own advisory on the same flaw four days later 3. Two national bodies on opposite sides of the Atlantic reached the same conclusion within a week, from a Polish alert written in Polish, which is roughly how fast a CERT-to-CERT signal travels when the underlying product is widely deployed.

Deep Analysis

In plain English

Zimbra is email server software that organisations run themselves instead of using a cloud service like Gmail. CERT Polska found attackers could take over a Zimbra server, without logging in, if two monitoring features happened to be switched on. Zimbra fixed the flaw in its 10.1.20 release. Anyone running an older version with those monitoring features enabled is exposed until they update.

Deep Analysis
Root Causes

CVE-2026-73570 only fires where SNMP notification and swatchdog are both enabled, features many Zimbra admins turn on for monitoring and then never revisit, so the attack surface tracks operational convenience rather than the mail server's core function.

Running exploited commands as the zimbra user, rather than root, still gives an attacker access to every mailbox the server hosts, since Zimbra's own service account owns that data.

First Reported In

Update #13 · Four privileged platforms under live attack

CERT Polska· 5 Sept 2026
Read original
Different Perspectives
ENISA
ENISA
ENISA published an SME cyber-resilience maturity model on 6 August and updated the Cyber Resilience Act reporting-platform FAQ on 31 August. The agency supplies common implementation tools for smaller operators, but it cannot fine organisations that do not use them.
UAE Cyber Security Council
UAE Cyber Security Council
On 10 August, the UAE Cyber Security Council said national teams contained attacks on aviation, energy and education before objectives were reached. Its second monthly statement, after a 3 July financial-sector disclosure, makes public reporting of stopped attacks part of its operating posture.
South African authorities
South African authorities
INTERPOL said on 25 August that South African authorities made 39 arrests, seized US$2.67 million and blocked 257 accounts during Operation Jackal IV. Their share of the 23-country operation shows the material enforcement burden in a cross-border fraud case.
Europol
Europol
On 2 September, Europol announced the sinkholing of Sality after a 31 August operation involving US, Bulgarian, Hungarian and Romanian authorities. Its more than 11 million linked IP addresses measure infrastructure contact, not confirmed victims, and show why technical partners joined the action.
CISA
CISA
From 3 August to 2 September, CISA recorded three-day deadlines for 24 of 37 KEV additions, compared with 34 of 39 from 10 June to 29 July. The falling share changes the urgency signal that US federal agencies and private-sector tooling draw from the catalogue.
Beacon
Beacon
On 3 September, Beacon said its final report found that an intruder likely exported its customer database during roughly one hour and 27 minutes on 27 July. Charities using the CRM now have a named exposure route, a compromised AWS access key in public build artefacts.