Critical Zimbra flaw has already compromised 270+ mail servers, CISA confirms active exploitation
CVE-2026-73570 lets an unauthenticated attacker run system commands through Zimbra's SNMP notification handling. Shadowserver counts hundreds of breached instances, with over 8,000 still unpatched.
Twenty days. That is roughly how long it took between the disclosure of CVE-2026-73570 and Shadowserver's count of 274 compromised Zimbra Collaboration Suite instances worldwide. The flaw, rated 8.9 on the CVSS scale, sits in how Zimbra processes SNMP notifications, and it lets an attacker with no credentials at all execute operating system commands as the zimbra user.
This is not a theoretical bug confined to a research writeup. The United States leads the compromised count with 46 instances, followed by Sweden with 21, France with 20 and Germany with 17. That spread says something specific: a lot of small and mid-sized organizations still run their own Zimbra mail server directly exposed to the internet, with no reverse proxy or web application firewall sitting in front of it.
CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on August 21, which triggers a mandatory patching deadline for US federal agencies. Everyone else gets the same advice without the legal obligation: upgrade to Zimbra Collaboration Suite 10.1.20 or later, now.
The United States leads the compromised count with 46 instances, followed by Sweden with 21, France with 20 and Germany with 17.
Patching alone may not be enough. Several researchers tracking the exploitation wave point out that updating a server after it has already been compromised does not remove whatever the attacker planted there, a backdoor account, a scheduled task, a webshell tucked into an upload directory. For any Zimbra deployment that was internet-facing before the patch landed, log review is the minimum, and a clean reinstall is the safer call if there is any doubt.
More than 8,200 instances remain unpatched according to the latest scans, a number that all but guarantees this list of compromised servers keeps growing through September. Mail servers make an unusually attractive target too: once inside, an attacker sits on every password reset link, every internal thread, every attachment that ever passed through the box.
SNMP notification handling being reachable without authentication is itself the part worth dwelling on. That subsystem exists to feed monitoring tools, not to process input from the open internet, and a pre-auth path into it suggests the kind of interface that rarely gets the same scrutiny as a login form. Zimbra has spent years positioning itself as the budget-friendly alternative to Exchange for ISPs, universities and government bodies that do not want a Microsoft licensing bill, which is exactly the demographic least likely to run a dedicated security team watching CISA's KEV catalog in real time.
Based on reporting by Help Net Security.




