At least 274 internet-facing Zimbra Collaboration Suite (ZCS) instances have been compromised through exploitation of CVE-2026-73570, a code injection vulnerability. The Shadowserver Foundation, a nonprofit security organization, reported the rising number of compromises after initially identifying 155 affected instances on August 20.
CVE-2026-73570 impacts Zimbra mail servers configured with the optional `zimbra-snmp` package and SNMP notifications enabled. The flaw stems from insufficient sanitization of untrusted input during SNMP notification processing. This allows an unauthenticated attacker to send specially crafted SMTP requests, potentially leading to the execution of arbitrary operating system commands under the privileges of the Zimbra user.
Synacor, the vendor behind Zimbra, released a patch for the vulnerability in ZCS version 10.1.20 on July 20, 2026. Prior to the official fix, the vulnerability was publicly disclosed on June 26, 2026, and a temporary mitigation was made available to administrators.
The in-the-wild exploitation of CVE-2026-73570 was first flagged by the Polish CERT, which provided indicators of compromise including specific log entries and created files. The Shadowserver Foundation leveraged this information in its daily internet-wide scans to identify compromised systems.
While at least 8,200 Zimbra instances have yet to update to ZCS v10.1.20, it's important to note that not all of these are necessarily vulnerable. The exploitability of CVE-2026-73570 is contingent on a non-default configuration, specifically the installation of the `zimbra-snmp` package and enabled SNMP notifications.
The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-73570 to its Known Exploited Vulnerabilities catalog. CISA has mandated that US federal civilian agencies address the vulnerability within three days and investigate for any signs of compromise. The identity of the attackers behind these ongoing exploits remains unknown.






