CYBERSECURITY

CISA Orders Urgent Patching of Actively Exploited Zimbra Flaw Within 72 Hours

CISA Orders Urgent Patching of Actively Exploited Zimbra Flaw Within 72 Hours

CISA Issues Emergency Directive After Zimbra Security Update

The directive follows Zimbra’s release of version 10.1.20 on July 20, which includes a patch for the security flaw. The vulnerability exists in the SNMP monitoring component and enables attackers to execute arbitrary code via command injection if SNMP notifications are active on the target server.

Root Cause Identified in SNMP Notification Processing

According to Zimbra’s technical analysis, the flaw stems from insufficient filtering of untrusted input during SNMP notification processing. This allows external attackers to send manipulated SMTP requests that, if processed successfully, can lead to arbitrary command execution at the operating system level under the Zimbra user’s privileges.

CISA Action Triggered by CERT Polska and Shadowserver Reports

CISA’s alert was prompted by preliminary findings from CERT Polska, which observed active exploitation of the flaw in the wild on Monday. The Shadowserver threat monitoring platform also reported over 12,000 exposed Zimbra server instances online, though it could not confirm how many were honeypots or already protected against CVE-2026-73570 exploitation.

Shadowserver Detects Over 270 Compromised Zimbra Servers

On the same Monday, Shadowserver identified more than 270 compromised Zimbra Collaboration Suite servers by analyzing artifacts linked to the vulnerability’s exploitation. These findings were later validated by CISA, which on Friday confirmed the CERT Polska alert, added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, and mandated that Federal Civilian Executive Branch (FCEB) agencies complete patching by August 24.

CISA Urges Log Reviews Despite Limited Attack Details

While CISA did not disclose specific details about the nature or scale of ongoing attacks, CERT Polska experts advised IT security teams to review system logs for suspicious signs, including unexpected Zimbra service restarts and unauthorized files created by the zimbra user in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/ within the last 30 days.

Zimbra Widely Used Across Government and Private Sectors

Zimbra Collaboration Suite is a widely deployed email and collaboration platform used by hundreds of millions of organizations and users worldwide, including numerous government agencies and thousands of private companies. Its vulnerability history shows a recurring pattern of exploitation in targeted attacks aimed at espionage and sensitive data exfiltration.

Past Exploits Link Zimbra to APT28 and APT29 Campaigns

For example, in March, Seqrite Labs researchers published evidence of a stored cross-site scripting (XSS) vulnerability exploited by APT28 — linked to Russian military intelligence — in targeted campaigns against Ukrainian government Zimbra servers, aiming to compromise email systems.

Joint U. S.-UK Warning Highlighted APT29 Zimbra Attacks in 2024

In October 2024, U. S. and UK cybersecurity agencies issued joint advisories about APT29 — also known as Midnight Blizzard and Cozy Bear, tied to Russia’s foreign intelligence service — exploiting a prior Zimbra flaw to steal email account credentials.

Russian-Linked Groups Also Target Zimbra via XSS Flaws

Additionally, incidents have been reported where threat actors associated with „Russian Winter Vivern,” linked to Russian cyber espionage operations, exploited reflected XSS vulnerabilities in Zimbra, further demonstrating the platform’s appeal as a target in sophisticated, long-running cyber campaigns.

Content written by Hannah Osei for tech-site.news editorial team, AI-assisted.

Comments

Leave a comment