Attackers are now breaking into vulnerable Zimbra email and collaboration servers, putting organizations that run them at immediate risk. CERT Polska says CVE-2026-73570, patched in Zimbra Collaboration Suite 10.1.20 on July 20, is being actively exploited. The bug is an unauthenticated command-injection flaw in the SNMP monitoring component when SNMP notifications are enabled, allowing specially crafted SMTP requests to run operating-system commands as the zimbra user. Shadowserver tracks more than 12,100 internet-exposed Zimbra servers.
Why it matters: Organizations using self-hosted Zimbra should treat this as an emergency because attackers do not need to log in to exploit it under the affected configuration. Update to 10.1.20 immediately, review logs and webapp/tmp directories for signs of compromise, and restrict or disable exposed attack paths where possible.
Sergiu Gatlan
2026.08.25
97% relevant
This directly updates the same event by adding confirmed compromise scale from Shadowserver: more than 270 Zimbra instances already breached, plus an estimate of at least 8,200 unpatched internet-exposed instances.
Sergiu Gatlan
2026.08.24
98% relevant
This article updates the same CVE-2026-73570 event by adding that CISA has now added the flaw to the KEV catalog and ordered U.S. federal agencies to patch by August 24, confirming active exploitation beyond CERT Polska's earlier warning.
Eduard Kovacs
2026.08.20
99% relevant
This article directly updates the same event by reporting SecurityWeek's coverage of CERT Polska's warning that CVE-2026-73570 is being exploited in the wild, adding context on affected versions, the optional zimbra-snmp component, and likely post-compromise impacts such as email access and lateral movement.
Sergiu Gatlan
2026.08.20
100% relevant
This article establishes a distinct new story by adding active in-the-wild exploitation to CVE-2026-73570, a critical Zimbra remote-code-execution flaw not represented in the existing tracked stories.
← Back to all stories