ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz1

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks

highExploit / PoC exploited in the wildimportance 78CVE-2026-73570
AI summary · glm-5.3-flash

Attackers are exploiting unpatched Zimbra servers via CVE-2026-73570; 274 instances compromised, and CISA added the flaw to its KEV catalog.

The Shadowserver Foundation counted at least 274 compromised internet-facing Zimbra Collaboration Suite instances exploited through CVE-2026-73570, up from 155 on August 20. The unauthenticated code injection flaw affects servers with the optional zimbra-snmp package and SNMP notifications enabled, allowing arbitrary OS command execution via crafted SMTP requests. Synacor patched the issue in ZCS v10.1.20 on July 20, 2026, and at least 8,200 instances remain unpatched. CISA added the flaw to its Known Exploited Vulnerabilities catalog and gave US federal civilian agencies three days to remediate and check for compromise.

  • 274 Zimbra instances compromised via CVE-2026-73570, per Shadowserver
  • Flaw requires non-default setup: zimbra-snmp package installed with SNMP notifications enabled
  • Polish CERT first flagged in-the-wild exploitation a week earlier
  • CISA KEV addition with a three-day federal remediation deadline
  • At least 8,200 servers remain unpatched to v10.1.20

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-73570
Unauthenticated OS Command Injection RCE in Synacor Zimbra Collaboration Suite

CVE-2026-73570 is an OS command injection vulnerability (CWE-78) in Synacor Zimbra Collaboration Suite (ZCS) before 10.1.20, caused by improper sanitization of untrusted input during SNMP notification processing. It is triggered when the optional zimbra-snmp package is installed and SNMP notifications are enabled: an unauthenticated attacker sends specially crafted SMTP requests that the flawed notification path turns into execution of arbitrary operating system commands. Successful exploitation runs commands as the Zimbra user, giving attackers control of the mail server's service account with high confidentiality and integrity impact across the host. Only ZCS deployments running the optional SNMP component with notifications enabled are vulnerable; other Zimbra installs are not exposed to this specific flaw. The flaw is under active exploitation: CISA added it to the KEV catalog on 2026-08-21, Poland's CERT has warned of in-the-wild attacks, unpatched Zimbra servers are reported compromised, and two public proof-of-concept exploits exist.

Do: Upgrade to Zimbra Collaboration Suite 10.1.20 or later per vendor instructions; as an interim mitigation, disable SNMP notifications or remove the zimbra-snmp package on hosts that do not need it. Federal operators must satisfy the CISA KEV/BOD 26-04 requirement, and all administrators of internet-facing Zimbra servers should hunt for signs of compromise (unexpected processes or persistence under the zimbra user) since unpatched systems are already being exploited.

8.932% KEV PoC ×4
  • Synacor Zimbra Collaboration Suite (ZCS) before 10.1.20 (when the optional zimbra-snmp package is installed and SNMP notifications are enabled)
large≈10,000-50,000 internet-exposed ZCS servers, with only the subset running zimbra-snmp with notifications enabled actually vulnerable
Full article355 words · extracted from helpnetsecurity.com · click to collapse

At least 274 internet-facing Zimbra instances have been compromised by unknown attackers via CVE-2026-73570, the Shadowserver Foundation shared on Monday.

About CVE-2026-73570

Zimbra Collaboration Suite (ZCS) is a communication and collaboration platform popular with organizations that need to have control over their data or can’t afford a pricy alternative service like Microsoft 365 or Google Workspace.

CVE-2026-73570 is a code injection flaw Synacor patched in ZCS v10.1.20, released on July 20, 2026.

The vulnerability was first disclosed on June 26, 2026, and admins were able to implement a temporary mitigation until the fix was released.

CVE-2026-73570 affects Zimbra mailservers that have the (optional) zimbra-snmp package installed and SNMP notifications enabled.

“Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user,” says the flaw’s CVE entry.

In-the-wild exploitation

The Polish CERT flagged in-the-wild exploitation of CVE-2026-73570 a week ago, and shared a list of log entries and created files that point to compromise.

With those available, the Shadowserver Foundation – a nonprofit that performs daily internet-wide scans covering most of the routable IPv4 address space, looking for open ports and services, TLS certificate data, vulnerability indicators, and more – flagged 155 compromised instances on August 20, and the number kept rising in the following days.

They also noted that there are at least 8200 instances that haven’t yet been updated to ZCS v10.1.20, but pointed out that not all may be open to attack via CVE-2026-73570, as the vulnerability is exploitable only in a non-default configuration.

The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-73570 to its Known Exploited Vulnerabilities catalog late last week, and ordered US federal civilian agencies to address it within three days and check for evidence of compromise.

Zimbra vulnerabilities are generally leveraged both by state-sponsored hackers (often as zero-days) and opportunistic cybercriminals. Who is behind these latest attacks is still unknown.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/08/25/zimbra-cve-2026-73570-compromised/