Attackers are actively exploiting a critical flaw in the Zimbra Collaboration Suite: CVE-2026-73570 allows code execution without authentication. Agencies and security researchers are warning – over 270 servers are already compromised.
Attack via SNMP
The cause is improper input validation when processing SNMP notifications. As a result, an unauthenticated attacker can execute arbitrary operating-system commands with the privileges of the “zimbra” user. Affected are installations where the optional “zimbra-snmp” package is installed and SNMP notifications are enabled.
Patch and scale
The flaw has been fixed since version 10.1.20, released on 20 July. The Shadowserver project found over 270 compromised Zimbra instances; more than 12,000 Zimbra mail servers are openly reachable on the internet and thus potentially exposed.
Deadlines set
CERT Polska warned of active exploitation on 17 August, and CISA added the flaw to its KEV catalog on 21 August (deadline for US agencies: 24 August). Anyone running Zimbra should update to 10.1.20 or newer immediately.
Sources: BleepingComputer, The Hacker News.



















