Hundreds of Zimbra Servers Exploited via Critical Code Execution Vulnerability (CVE-2026-73570)

A critical vulnerability in Zimbra Collaboration Suite (ZCS) is actively being exploited, leaving numerous internet-facing servers at risk. The flaw, identified as CVE-2026-73570, allows unauthenticated attackers to execute arbitrary code on affected systems via the SNMP monitoring component when enabled. Multiple sources indicate that a significant number of Zimbra instances are vulnerable, with reports confirming at least 274 servers have already been compromised by unknown threat actors.

CVE-2026-73570 is classified as a code injection vulnerability stemming from improper sanitization of untrusted input during SNMP notification processing. This allows attackers to execute OS commands as the Zimbra user, potentially granting them complete control over the server and its data. The vulnerability was disclosed in late June 2026 and patched in ZCS v10.1.20 on July 20.

The exploitation of CVE-2026-73570 has been confirmed by several cybersecurity firms and government agencies. CERT Polska first reported signs of active exploitation in late August 2026, triggering widespread alerts within the security community. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) subsequently issued a three-day deadline for federal agencies to patch the vulnerability by August 24, emphasizing the severity of the threat and the urgency of remediation efforts.

The CVSS score assigned to CVE-2026-73570 reflects its high potential impact – a score of 8.9 indicates a critical vulnerability that could lead to significant data breaches or system compromise. While the exact methods used by attackers are not fully detailed, the ease with which code can be injected via SNMP suggests a relatively simple attack vector.

Organizations using Zimbra Collaboration Suite must immediately assess their environments for vulnerability to CVE-2026-73570 and apply the available patch (ZCS v10.1.20). Those unable to immediately patch should review Zimbra’s temporary mitigation guidance, though this is not a substitute for applying the official fix. The ongoing exploitation of this critical vulnerability underscores the importance of maintaining up-to-date patching practices and regularly monitoring systems for signs of compromise.

Sources: