Bottom line: Zimbra servers are at high risk of successful exploitation if not patched.
What's happening: Exploitation of the Zimbra Collaboration vulnerability CVE-2026-73570 has been observed by Poland’s CERT Polska, targeting Zimbra servers in Eastern Europe. The vulnerability has a CVSS score of 7.8.
What to do: Security teams should prioritize patching the Zimbra Collaboration vulnerability, and implement additional security controls to prevent lateral movement. CERT Polska advises organizations to check their Zimbra server configurations for potential vulnerabilities.