Active Attacks Target Zimbra Email Servers via Newly Disclosed Flaw
Cybersecurity authorities in Poland (CERT Polska) have confirmed active exploitation of a vulnerability in Zimbra Collaboration, a popular email and collaboration platform used by organisations worldwide, including small and medium businesses. The flaw, tracked as CVE-2026-73570, is being targeted by attackers in real-world campaigns, meaning organisations running affected Zimbra servers may already be at risk.
Email servers are a prime target for cybercriminals because they often hold sensitive communications, credentials, and access to broader business systems. When vulnerabilities like this are actively exploited, delays in patching can quickly turn into serious incidents such as data theft, account compromise, or further network intrusion.
While full technical details of the vulnerability are still emerging, the fact that it is already being exploited in the wild underscores the urgency for businesses using Zimbra to check their systems and apply any available updates as soon as possible. Businesses relying on third-party IT providers to manage their email infrastructure should confirm with their provider that this issue is being addressed.