Attackers begin exploiting Zimbra Collaboration remote-code-execution flaw CVE-2026-73570

Attackers are now breaking into vulnerable Zimbra email and collaboration servers, putting organizations that run them at immediate risk. CERT Polska says CVE-2026-73570, patched in Zimbra Collaboration Suite 10.1.20 on July 20, is being actively exploited. The bug is an unauthenticated command-injection flaw in the SNMP monitoring component when SNMP notifications are enabled, allowing specially crafted SMTP requests to run operating-system commands as the zimbra user. Shadowserver tracks more than 12,100 internet-exposed Zimbra servers.
Why it matters: Organizations using self-hosted Zimbra should treat this as an emergency because attackers do not need to log in to exploit it under the affected configuration. Update to 10.1.20 immediately, review logs and webapp/tmp directories for signs of compromise, and restrict or disable exposed attack paths where possible.

Sources

Hackers breached over 270 Zimbra servers in ongoing attacks
Sergiu Gatlan 2026.08.25 97% relevant
This directly updates the same event by adding confirmed compromise scale from Shadowserver: more than 270 Zimbra instances already breached, plus an estimate of at least 8,200 unpatched internet-exposed instances.
CISA orders urgent patching of actively exploited Zimbra flaw
Sergiu Gatlan 2026.08.24 98% relevant
This article updates the same CVE-2026-73570 event by adding that CISA has now added the flaw to the KEV catalog and ordered U.S. federal agencies to patch by August 24, confirming active exploitation beyond CERT Polska's earlier warning.
Hackers Target Zimbra Servers in Active Exploitation Campaign
Eduard Kovacs 2026.08.20 99% relevant
This article directly updates the same event by reporting SecurityWeek's coverage of CERT Polska's warning that CVE-2026-73570 is being exploited in the wild, adding context on affected versions, the optional zimbra-snmp component, and likely post-compromise impacts such as email access and lateral movement.
Critical Zimbra RCE flaw now actively exploited in attacks
Sergiu Gatlan 2026.08.20 100% relevant
This article establishes a distinct new story by adding active in-the-wild exploitation to CVE-2026-73570, a critical Zimbra remote-code-execution flaw not represented in the existing tracked stories.
← Back to all stories