Unpatched Zimbra servers are falling to CVE-2026-73570 attacks
Reported exploitedZimbra Collaboration SuiteOur summary
Shadowserver reports that at least 274 internet-exposed Zimbra Collaboration Suite instances have been breached through active exploitation of CVE-2026-73570. This unauthenticated code injection vulnerability impacts installations using the optional zimbra-snmp package with SNMP notifications enabled, allowing attackers to execute arbitrary OS commands.
Synacor released a patch in version 10.1.20 on July 20, 2026, and CISA has now added the issue to its Known Exploited Vulnerabilities catalog, mandating remediation for federal agencies. With thousands of potentially vulnerable systems still unpatched, administrators are urged to apply the update immediately and audit their systems for signs of intrusion.
Help Net Security publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.