Skip to content
Rush Commerce
Software & Dev3 min read

Zimbra CVE-2026-73570: 274 breached, patch shipped July 20

An unauthenticated RCE in Zimbra's SNMP handling is being exploited in the wild. 274 confirmed compromises, ~8,200 servers still unpatched five weeks after the fix.

Zimbra shipped the patch on July 20. CISA added CVE-2026-73570 to its Known Exploited Vulnerabilities catalog on August 21. As of today, Shadowserver counts 274 compromised internet-facing Zimbra instances and roughly 8,200 that still have not moved to the fixed release. Five weeks between the fix and the breach count is the whole story here, and it is a story about mail servers nobody owns.

What actually happened

CVE-2026-73570 is an OS command injection flaw in Zimbra Collaboration Suite. Per Help Net Security, an unauthenticated attacker can send crafted SMTP requests that end in arbitrary commands executing as the zimbra user, because input is not sanitized during SNMP notification processing. Exploitation requires the optional zimbra-snmp package installed with SNMP notifications enabled — not the default configuration, which is why the 8,200 figure is an upper bound on exposure rather than a victim count.

The timeline, per Help Net Security and BleepingComputer: initial disclosure with a temporary mitigation on June 26. Patch in ZCS 10.1.20 on July 20. CERT Polska flagged active exploitation in mid-August. Shadowserver counted 155 compromised instances on August 20 and 274 by today. CISA added the CVE to KEV on August 21 and gave federal civilian agencies three days to remediate.

CERT Polska's indicators are cheap to check: unexpected Zimbra service restarts in your logs, and files created by the zimbra user in the last 30 days under /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, or /tmp/.

Why an unpatched mail server matters for your business

Mail servers are the highest-value box you forgot you run. Self-hosted Zimbra usually exists because somebody wanted to avoid per-seat licensing years ago. It holds every invoice, every contract negotiation, and every password reset link your company has ever received. Code execution on that host is not a data breach in the abstract — it is an attacker reading your accounts payable thread and then sending a wiring instruction from a real address.

An optional package is still an installed package. "SNMP is not our default" is a fine sentence and a terrible control. Somebody enabled monitoring in 2021 and moved on. Check the box, do not check your memory.

Patched is not the same as clean. Five weeks of exposure means updating to 10.1.20 stops the next attacker and does nothing about the one who already landed. Run the CERT Polska file checks before you close the ticket. A webshell dropped in webapps/ survives a version bump.

Three days was the federal deadline, not a stretch goal. CISA gave FCEB agencies 72 hours. If your patch cadence for an internet-facing mail server is measured in weeks, this CVE is showing you what that costs.

Key takeaways

  • CVE-2026-73570 is an unauthenticated OS command injection in Zimbra Collaboration Suite's SNMP notification handling, reachable over SMTP
  • Fixed in ZCS 10.1.20, released July 20, 2026; a temporary mitigation existed from June 26
  • CISA added it to the KEV catalog on August 21 with a three-day federal remediation deadline
  • Shadowserver: 155 compromised instances on August 20, 274 by August 25; roughly 8,200 still unpatched
  • Exploitation requires the optional zimbra-snmp package with notifications enabled — verify, do not assume
  • Check for unexpected service restarts and recent zimbra-owned files in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/

If nobody's name is on the mail server, nobody patches it. We inventory what you actually run, put an owner and a cadence on each piece, and document it so the answer takes one command instead of one meeting. See how we work, or tell us what's still on your perimeter.

Sources: Help Net Security, BleepingComputer, CISA KEV alert, August 21, 2026.

  • #cve-2026-73570
  • #zimbra
  • #patch-management
  • #vulnerability
  • #cisa-kev
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.