Mass exploitation of Zimbra SNMP flaw (CVE-2026-73570) compromises hundreds of mail servers
Attackers exploited CVE-2026-73570, an unauthenticated command injection flaw in Zimbra Collaboration Suite's SNMP notification handling, compromising at least 274 internet-facing mail servers within days of CERT Polska confirming exploitation.
- Victim
- Zimbra Collaboration Suite
On 17 August 2026, CERT Polska confirmed that attackers were actively exploiting CVE-2026-73570, a command injection vulnerability in Zimbra Collaboration Suite (ZCS). The flaw affects servers that run the optional zimbra-snmp package with SNMP notifications enabled, and lets an unauthenticated attacker run arbitrary operating system commands as the Zimbra user by sending specially crafted SMTP requests. It carries a CVSS score of 8.9.
Zimbra had fixed the bug in version 10.1.20, released on 20 July 2026, but exploitation began about four weeks later against servers that had not been updated. Scanning by the Shadowserver Foundation found 155 compromised instances by 20 August and 274 by 22 August, a 77 percent jump in 48 hours, while roughly 8,200 internet-facing instances remained unpatched (not all of them exposed through the non-default SNMP configuration).
Response
On 21 August, CISA added CVE-2026-73570 to its Known Exploited Vulnerabilities catalog and gave U.S. federal civilian agencies just three days to patch and to look for signs of compromise. No specific threat actor had been publicly tied to the campaign. Zimbra flaws have previously been exploited both by state-sponsored espionage groups seeking access to government mailboxes and by financially motivated criminals.
Why it matters
Mail servers hold the correspondence, credentials and password-reset flows of entire organizations, which makes self-hosted Zimbra deployments in governments, universities and smaller companies a recurring target. The month-long gap between patch release and mass exploitation, followed by a near-doubling of victims in two days, illustrates how quickly unpatched on-premises email infrastructure is swept up once working exploits circulate.
Timeline
Zimbra releases ZCS 10.1.20, fixing CVE-2026-73570.
CERT Polska confirms active exploitation of the flaw.
Shadowserver flags 155 compromised Zimbra instances.
CISA adds CVE-2026-73570 to its Known Exploited Vulnerabilities catalog with a three-day federal remediation deadline.
Shadowserver's count of compromised instances reaches 274, with about 8,200 servers still unpatched.
Sources
- helpnetsecurity.comhttps://www.helpnetsecurity.com/2026/08/25/zimbra-cve-2026-73570-compromised/
- thehackernews.comhttps://thehackernews.com/2026/08/attackers-exploit-zimbra-snmp-flaw-for.html
- bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/cisa-orders-urgent-patching-of-actively-exploited-zimbra-flaw/
- labs.cloudsecurityalliance.orghttps://labs.cloudsecurityalliance.org/research/csa-research-note-zimbra-cve-2026-73570-snmp-nation-state-20/