"Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user," the Zimbra security team warned.
The Zimbra flaw (CVE-2026-73570) and how it works
Zimbra Collaboration Suite (ZCS) contains a command-injection weakness tracked as CVE-2026-73570. The vendor released a patch in version 10.1.20 on July 20. According to Zimbra's advisory, the vulnerability exists in the SNMP monitoring component when SNMP notifications are enabled: improper sanitization of untrusted input during SNMP notification processing can allow an unauthenticated attacker to gain remote code execution. The advisory says an attacker may send "specially crafted SMTP requests" that result in execution of arbitrary operating system commands under the Zimbra user.
CISA's emergency order and timeline
The Cybersecurity and Infrastructure Security Agency confirmed CERT Polska's alert and added CVE-2026-73570 to its Known Exploited Vulnerabilities (KEV) catalog. CISA ordered U.S. Federal Civilian Executive Branch (FCEB) agencies to secure affected systems within three days; the deadline given was August 24. The agency did not publish technical details of the ongoing attacks in its bulletin.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildObserved exploitation and CERT Polska's detection guidance
CERT Polska first flagged the vulnerability as being targeted in the wild the Monday before CISA's action. While CISA did not share operational specifics, CERT Polska advised security teams to check logs for suspicious activity, including unexpected Zimbra service restarts, and to look for files created by the zimbra user over the last 30 days in these locations: /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/. Those checks are presented as immediate triage steps to detect potential compromise stemming from this command-injection vector.
Zimbra's scale and a pattern of targeted exploitation
Shadowserver tracks more than 12,000 Zimbra servers exposed on the Internet, though the tracker says it cannot determine how many of those are honeypots or have already been secured against CVE-2026-73570. ZCS is widely deployed: the vendor and reporting note it is used by "hundreds of millions of organizations and people worldwide," including hundreds of government agencies and thousands of businesses. The product has been a repeated target: researchers and government agencies have documented multiple campaigns exploiting Zimbra flaws to steal email and credentials in recent years.
The source lists several named incidents: Seqrite Labs reported in March that APT28 exploited a stored cross-site scripting (XSS) vulnerability to target Ukrainian government ZCS servers. In October 2024, U.S. and U.K. cyber agencies warned that APT29 (tracked as Midnight Blizzard and Cozy Bear) targeted Zimbra servers using a previously exploited flaw to steal email account credentials. Russian Winter Vivern cyber spies also abused a reflected XSS vulnerability to steal emails belonging to NATO-aligned individuals and organizations via Zimbra webmail portals.
What this means for technologists, federal agencies, and businesses
- Technologists and security teams: The immediate task is to apply Zimbra 10.1.20 or other vendor mitigations, verify SNMP notification settings, and follow CERT Polska's log and filesystem checks for signs of post-exploitation activity by the zimbra user.
- Federal agencies (FCEB): CISA's three-day order makes this a compliance and operational priority with a hard deadline (August 24) to secure systems listed under the KEV action; agencies must reconcile the order with inventory and patching processes to meet that timeline.
- Businesses that run ZCS: Organizations outside the FCEB footprint should treat the KEV addition and the reports of targeted exploitation as a high-priority risk signal—particularly if SNMP notifications are enabled or if public exposure of Zimbra services is confirmed by scanners such as Shadowserver.
There are clear, immediate steps—patch, inspect, and harden—but several operational uncertainties remain in the public record: CISA did not share details of the ongoing attacks, and Shadowserver's count of "more than 12,000" exposed servers does not distinguish active targets from honeypots or already-mitigated systems. The record does show, however, that Zimbra servers are both numerous and repeatedly attractive to attackers, and that defenders' ability to stop adversaries falls once attackers obtain valid credentials—a point underscored by the Blue Report 2026's finding that "overall prevention scores can hide what happens after initial access" across 338 million simulated runs.
The immediate question for defenders is operational: who has ZCS with SNMP notifications enabled, and can they reach and patch those instances before exploitation advances? For now the actionable facts are simple and stark—patch to 10.1.20, search the specified directories and logs for signs of compromise, and treat the KEV listing and CISA order as signals that the threat is active.




