Skip to content
Vulnerability exploitOngoing

Mass exploitation of Zimbra SNMP flaw (CVE-2026-73570) compromises hundreds of mail servers

Attackers exploited CVE-2026-73570, an unauthenticated command injection flaw in Zimbra Collaboration Suite's SNMP notification handling, compromising at least 274 internet-facing mail servers within days of CERT Polska confirming exploitation.

Victim
Zimbra Collaboration Suite
CVECVE-2026-73570

On 17 August 2026, CERT Polska confirmed that attackers were actively exploiting CVE-2026-73570, a command injection vulnerability in Zimbra Collaboration Suite (ZCS). The flaw affects servers that run the optional zimbra-snmp package with SNMP notifications enabled, and lets an unauthenticated attacker run arbitrary operating system commands as the Zimbra user by sending specially crafted SMTP requests. It carries a CVSS score of 8.9.

Zimbra had fixed the bug in version 10.1.20, released on 20 July 2026, but exploitation began about four weeks later against servers that had not been updated. Scanning by the Shadowserver Foundation found 155 compromised instances by 20 August and 274 by 22 August, a 77 percent jump in 48 hours, while roughly 8,200 internet-facing instances remained unpatched (not all of them exposed through the non-default SNMP configuration).

Response

On 21 August, CISA added CVE-2026-73570 to its Known Exploited Vulnerabilities catalog and gave U.S. federal civilian agencies just three days to patch and to look for signs of compromise. No specific threat actor had been publicly tied to the campaign. Zimbra flaws have previously been exploited both by state-sponsored espionage groups seeking access to government mailboxes and by financially motivated criminals.

Why it matters

Mail servers hold the correspondence, credentials and password-reset flows of entire organizations, which makes self-hosted Zimbra deployments in governments, universities and smaller companies a recurring target. The month-long gap between patch release and mass exploitation, followed by a near-doubling of victims in two days, illustrates how quickly unpatched on-premises email infrastructure is swept up once working exploits circulate.

Timeline

  1. Zimbra releases ZCS 10.1.20, fixing CVE-2026-73570.

  2. CERT Polska confirms active exploitation of the flaw.

  3. Shadowserver flags 155 compromised Zimbra instances.

  4. CISA adds CVE-2026-73570 to its Known Exploited Vulnerabilities catalog with a three-day federal remediation deadline.

  5. Shadowserver's count of compromised instances reaches 274, with about 8,200 servers still unpatched.

Sources

  1. helpnetsecurity.comhttps://www.helpnetsecurity.com/2026/08/25/zimbra-cve-2026-73570-compromised/
  2. thehackernews.comhttps://thehackernews.com/2026/08/attackers-exploit-zimbra-snmp-flaw-for.html
  3. bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/cisa-orders-urgent-patching-of-actively-exploited-zimbra-flaw/
  4. labs.cloudsecurityalliance.orghttps://labs.cloudsecurityalliance.org/research/csa-research-note-zimbra-cve-2026-73570-snmp-nation-state-20/

Related incidents

Vulnerability exploitOngoing

CISA warns of actively exploited on-premises SharePoint Server flaws (CVE-2026-56164, CVE-2026-45659, CVE-2026-32201)

CISA issued an urgent hardening alert after confirming that attackers were chaining three vulnerabilities in on-premises Microsoft SharePoint Server โ€” including an unauthenticated missing-authentication bug the U.S. National Vulnerability Database rates critical โ€” to reach remote code execution, steal IIS machine keys and deploy malware.

Victim
Microsoft SharePoint Server