Hackers target Zimbra servers in active exploitation campaign
THE BRIEF
Attackers are actively exploiting CVE-2026-73570 in Zimbra Collaboration, according to observations cited by Poland’s CERT Polska. Internet-facing email and collaboration platforms are high-value targets because successful compromise can expose mailboxes, authentication material and trusted internal communication channels that support follow-on phishing or lateral movement. Organizations operating Zimbra should move beyond normal patch-cycle timing: identify exposed instances, apply the relevant security update and investigate whether exploitation occurred before remediation. Email servers often contain long-lived sensitive information and can be used to impersonate trusted staff, making post-patch threat hunting as important as installing the fix itself.
WHY IT MATTERS
Active exploitation changes the risk calculation from theoretical exposure to a live incident possibility. Email infrastructure sits at the intersection of identity, confidential information and business trust, so a compromised server can support credential theft, internal phishing and persistence. European organizations should pay particular attention given the CERT Polska observation, but internet-facing Zimbra deployments globally face the same underlying exposure. Teams should verify patch coverage, inspect historical logs and rotate sensitive credentials if evidence suggests an attacker reached administrative or mailbox data.
WHO SHOULD CARE
Email administrators, SOC teams, vulnerability management, identity teams, managed service providers and organizations running self-hosted Zimbra Collaboration.
WHAT TO DO NOW
- Identify every internet-facing Zimbra instance and confirm whether CVE-2026-73570 applies.
- Apply the vendor security update immediately and verify successful deployment.
- Review web, authentication and administrative logs for exploitation attempts preceding the patch.
- Investigate suspicious mailbox rules, delegated access, new administrators and unusual session activity.
- Rotate credentials and tokens where evidence indicates privileged or mailbox compromise.
VERIFICATION NOTE
Verified against the cited source; claims are summarized conservatively and attacker assertions are identified as unconfirmed where applicable.