CVE Tools

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks

Help Net SecurityBy Zeljka Zorz

Reported exploitedZimbra Collaboration Suite

Our summary

Shadowserver reports that at least 274 internet-exposed Zimbra Collaboration Suite instances have been breached through active exploitation of CVE-2026-73570. This unauthenticated code injection vulnerability impacts installations using the optional zimbra-snmp package with SNMP notifications enabled, allowing attackers to execute arbitrary OS commands.

Synacor released a patch in version 10.1.20 on July 20, 2026, and CISA has now added the issue to its Known Exploited Vulnerabilities catalog, mandating remediation for federal agencies. With thousands of potentially vulnerable systems still unpatched, administrators are urged to apply the update immediately and audit their systems for signs of intrusion.

Read at Help Net Security

Help Net Security publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store