Unpatched Zimbra Servers Under Active Attack: What SMBs Need to Know
A critical vulnerability in Zimbra Collaboration (ZCS), the email and collaboration platform used by many small and medium businesses, is being actively exploited by attackers, according to Poland's national cyber emergency team (CERT Polska). The flaw, tracked as CVE-2026-73570, carries a high severity score of 8.9 out of 10 and allows attackers to inject malicious commands into a vulnerable server without needing a username or password.
Because this is a command injection vulnerability leading to remote code execution, successful exploitation could let attackers fully control an affected Zimbra server — potentially accessing sensitive company emails, customer data, or using the compromised system as a launchpad for further attacks within a business network. A patch for this vulnerability has already been released by Zimbra, meaning the risk now falls squarely on organisations that haven't yet applied the update.
For Australian small businesses relying on Zimbra for email and collaboration, this is a timely reminder that email servers are high-value targets for cybercriminals. Delaying software updates, even briefly, can leave a business exposed to automated attacks scanning the internet for unpatched systems.