Security News

Active Attacks Target Zimbra Email Servers via Newly Disclosed Flaw

Security Week · 21 Aug 2026
Key Takeaway If your business uses Zimbra Collaboration for email, check for and apply security updates immediately, and ask your IT provider to confirm the system has been patched against CVE-2026-73570.

Cybersecurity authorities in Poland (CERT Polska) have confirmed active exploitation of a vulnerability in Zimbra Collaboration, a popular email and collaboration platform used by organisations worldwide, including small and medium businesses. The flaw, tracked as CVE-2026-73570, is being targeted by attackers in real-world campaigns, meaning organisations running affected Zimbra servers may already be at risk.

Email servers are a prime target for cybercriminals because they often hold sensitive communications, credentials, and access to broader business systems. When vulnerabilities like this are actively exploited, delays in patching can quickly turn into serious incidents such as data theft, account compromise, or further network intrusion.

While full technical details of the vulnerability are still emerging, the fact that it is already being exploited in the wild underscores the urgency for businesses using Zimbra to check their systems and apply any available updates as soon as possible. Businesses relying on third-party IT providers to manage their email infrastructure should confirm with their provider that this issue is being addressed.

Summarised by CISO AI from Security Week. We link back to every original so you can read it yourself.